Common port exploit weaknesses

21

FTP

Mainly to see whether to support anonymous, can also be run weak passwords

 

22

SSH

Weak passwords blasting

 

23

telnet

Weak passwords blasting

 

80-90

WEB

Common WEB vulnerability as well as some management background

 

161

snmp

public weak passwords

 

389

ldap

Whether anonymous access

 

443

openssl

Bleeding heart and some WEB vulnerability testing

 

445

smb

Run weak passwords, detecting whether ms_08067 like overflow

 

873

rsync

Whether anonymous access, you can also run weak passwords

 

1025

RPC

NFS anonymous access

 

1099

java

rmi

Remote Command Execution Vulnerability

1433

mssql

Weak passwords blasting

 

1521

oracle

Weak passwords blasting

 

2082/2083

cpanel host management system landing

Weak passwords blasting

 

2222

DA virtual host management system landing

Weak passwords blasting

 

2601,2604

zebra router

The default password zebra

 

3128

squid proxy default port

If no password is likely set

It is within direct roaming network

3306

mysql

Weak passwords blasting

 

3312/3311

kangle host management system landing

Explanation

 

3389

RDP

Weak passwords blasting, SHIFT back door, magnifying glass, input holes

 

4440

rundeck

web

 

4848

GlassFish

web middleware

Weak password admin / adminadmin

5432

postgres

Weak passwords blasting

 

5560,7778

iSqlPlus

5900,5901,5902

vnc

6082

varnish

 

 

6379

repeat

Usually no verification, direct access

 

7001,7002

weblogic

Weak passwords blasting

 

7778

Kloxo hosting control panel login

8080

tomcat\jboss

Weak passwords blasting, jboss background may not be verified

 

 

 

8649

ganglia

8080-8090

Common WEB port

8083

Vestacp host management system

(Abroad with more)

 

8649

ganglia

8888

AMH / LuManager

9000

fcgi

fcgi

php command execution vulnerability

9200

elasticsearch

Code execution

 

9043

websphere

弱口令爆破

 

10000

Virtualmin/Webmin

服务器虚拟主机管理系统

11211

27017,28017

mongodb

未授权访问

 

50000

Upnp

SAP命令执行

 

50060,50030

hadoop

WEB

未授权访问

21 ftp 主要看是否支持匿名,也可以跑弱口令
80 web 常见web漏洞以及是否为一些管理后台
443 openssl 心脏滴血以及一些web漏洞测试
873 rsync 主要看是否支持匿名,也可以跑弱口令
1900 bes默认管理后台
2082/2083 cpanel主机管理系统登陆 (国外用较多)?
2222 DA虚拟主机管理系统登陆 (国外用较多)
2601,2604 zebra路由,默认密码zebra
3128 squid代理默认端口,如果没设置口令很可能就直接漫游内网了
3312/3311 kangle主机管理系统登陆
4440 rundeck 参考WooYun: 借用新浪某服务成功漫游新浪内网
6082 varnish 参考WooYun: Varnish HTTP accelerator CLI 未授权访问易导致网站被直接篡改或者作为代理进入内网
6379 redis 一般无认证,可直接访问
7001 weblogic,默认弱口令
7778 Kloxo主机控制面板登录?
8080 tomcat/WDCP主机管理系统 默认端口 默认用户名密码 admin  wdlinux.cn
  Mysql默认的用户名密码 root   wdlinux.cn
8083 Vestacp主机管理系统?? (国外用较多)
8089 jboss端口 历史曾经爆漏洞/可弱口令
8649 ganglia信息泄漏
8888 amh/LuManager 主机管理系统默认端口
8000-9090 都是一些常见的web端口,有些运维喜欢把管理后台开在这些非80的端口上
9200 elasticsearch 参考WooYun: 多玩某服务器ElasticSearch命令执行漏洞
?10000 Virtualmin/Webmin 服务器虚拟主机管理系统
11211 memcache 未授权访问
27017 mongodb 未授权访问
28017 mongodb统计页面
50000 SAP命令执行
50030/50070 hadoop默认端口

Guess you like

Origin www.cnblogs.com/mutudou/p/11767299.html