Skip to content

111 - Pentesting rpc

Enumeration

rpcinfo $(target)
sudo nmap -sS -sC -sV -p 111 $(target)
sudo nmap -sS -sU -sC -sV -p 111 $(target)

Scripts

nmap -p 111 --script=rpcinfo  $(target)
nmap -p 111 --script=nfs-ls  $(target)
nmap -p 111 --script=nfs-statfs  $(target)
nmap -p 111 --script=nfs-showmount  $(target)
rpcclient -U "" -N $(target)
rpcinfo -p $(target)
showmount -e $(target)

mount folder

sudo mkdir /mnt/target_dir
sudo mount $(target):/home/user /mnt/target_dir/

mount nfs resource (v1)

service rpcbind start
mkdir /tmp/target
sudo mount -t nfs 10.0.2.5:/ /tmp/target
cd /tmp/target
sudo umount /tmp/target

mount nfs resource (v2)

mkdir home_shared
sudo mount -o nolock 10.11.1.32:/home ~/home_shared/