21 |
FTP |
Mainly to see whether to support anonymous, can also be run weak passwords |
|
22 |
SSH |
Weak passwords blasting |
|
23 |
telnet |
Weak passwords blasting |
|
80-90 |
WEB |
Common WEB vulnerability as well as some management background |
|
161 |
snmp |
public weak passwords |
|
389 |
ldap |
Whether anonymous access |
|
443 |
openssl |
Bleeding heart and some WEB vulnerability testing |
|
445 |
smb |
Run weak passwords, detecting whether ms_08067 like overflow |
|
873 |
rsync |
Whether anonymous access, you can also run weak passwords |
|
1025 |
RPC |
NFS anonymous access |
|
1099 |
java |
rmi |
Remote Command Execution Vulnerability |
1433 |
mssql |
Weak passwords blasting |
|
1521 |
oracle |
Weak passwords blasting |
|
2082/2083 |
cpanel host management system landing |
Weak passwords blasting |
|
2222 |
DA virtual host management system landing |
Weak passwords blasting |
|
2601,2604 |
zebra router |
The default password zebra |
|
3128 |
squid proxy default port |
If no password is likely set |
It is within direct roaming network |
3306 |
mysql |
Weak passwords blasting |
|
3312/3311 |
kangle host management system landing |
Explanation |
|
3389 |
RDP |
Weak passwords blasting, SHIFT back door, magnifying glass, input holes |
|
4440 |
rundeck |
web |
|
4848 |
GlassFish |
web middleware |
Weak password admin / adminadmin |
5432 |
postgres |
Weak passwords blasting |
|
5560,7778 |
iSqlPlus |
5900,5901,5902 |
vnc |
6082 |
varnish |
|
|
6379 |
repeat |
Usually no verification, direct access |
|
7001,7002 |
weblogic |
Weak passwords blasting |
|
7778 |
Kloxo hosting control panel login |
8080 |
tomcat\jboss |
Weak passwords blasting, jboss background may not be verified |
|
|
|
8649 |
ganglia |
8080-8090 |
Common WEB port |
8083 |
Vestacp host management system |
(Abroad with more) |
|
8649 |
ganglia |
8888 |
AMH / LuManager |
9000 |
fcgi |
fcgi |
php command execution vulnerability |
9200 |
elasticsearch |
Code execution |
|
9043 |
websphere |
弱口令爆破 |
|
10000 |
Virtualmin/Webmin |
服务器虚拟主机管理系统 |
11211 |
27017,28017 |
mongodb |
未授权访问 |
|
50000 |
Upnp |
SAP命令执行 |
|
50060,50030 |
hadoop |
WEB |
未授权访问 |
21 ftp 主要看是否支持匿名,也可以跑弱口令
80 web 常见web漏洞以及是否为一些管理后台
443 openssl 心脏滴血以及一些web漏洞测试
873 rsync 主要看是否支持匿名,也可以跑弱口令
1900 bes默认管理后台
2082/2083 cpanel主机管理系统登陆 (国外用较多)?
2222 DA虚拟主机管理系统登陆 (国外用较多)
2601,2604 zebra路由,默认密码zebra
3128 squid代理默认端口,如果没设置口令很可能就直接漫游内网了
3312/3311 kangle主机管理系统登陆
4440 rundeck 参考WooYun: 借用新浪某服务成功漫游新浪内网
6082 varnish 参考WooYun: Varnish HTTP accelerator CLI 未授权访问易导致网站被直接篡改或者作为代理进入内网
6379 redis 一般无认证,可直接访问
7001 weblogic,默认弱口令
7778 Kloxo主机控制面板登录?
8080 tomcat/WDCP主机管理系统 默认端口 默认用户名密码 admin wdlinux.cn
Mysql默认的用户名密码 root wdlinux.cn
8083 Vestacp主机管理系统?? (国外用较多)
8089 jboss端口 历史曾经爆漏洞/可弱口令
8649 ganglia信息泄漏
8888 amh/LuManager 主机管理系统默认端口
8000-9090 都是一些常见的web端口,有些运维喜欢把管理后台开在这些非80的端口上
9200 elasticsearch 参考WooYun: 多玩某服务器ElasticSearch命令执行漏洞
?10000 Virtualmin/Webmin 服务器虚拟主机管理系统
11211 memcache 未授权访问
27017 mongodb 未授权访问
28017 mongodb统计页面
50000 SAP命令执行
50030/50070 hadoop默认端口