Network service enumeration & attack
SkillDatabases & dataAttack non-web network services surfaced by recon. Load when nmap shows services like SMB (445), RPC (135), LDAP (389), SNMP (161), NFS (2049), SMTP (25), FTP (21), RDP (3389), databases (3306/5432/1433/6379/27017). Signals: open non-HTTP ports, service+version banners.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Network service enumeration & attack skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/network/network-service-attacks/SKILL.md and read by ahel’s review.
When it applies
Recon exposed non-web services. Each is its own attack surface: anonymous access, default/weak
creds, known-CVE versions, and info leaks that feed the next step. (See recon-arsenal for the
discovery arsenal; this is the exploit routing per service.)
Why it works
Internal-style services are frequently deployed with defaults, anonymous binds, or no auth because they were "not meant to be exposed". Version banners map straight to public exploits.
Method
- Always version-map first — the exact product+version is the fastest lead (
nmap -sCV). - Route by service:
- SMB (445):
nxc smb <ip> -u '' -p ''(null session),enum4linux-ng, list shares (smbclient -L //ip -N), check forEternalBlue/signing; spray creds with netexec. - LDAP (389/636): anonymous bind dump (
ldapsearch -x -H ldap://ip -b <base>) → users. - SNMP (161):
snmpwalk -v2c -c public ip— leaks processes, users, routes, sometimes creds. - NFS (2049):
showmount -e ip; mount world-readable exports, checkno_root_squash. - SMTP (25):
VRFY/RCPTuser enumeration. - DBs: try default creds; Redis (6379) often unauth (→
web-ssrf-gopher-redis-rceif internal).
- SMB (445):
- Map version → CVE:
searchsploit <product version>; verify before firing.
Gotchas
- Null/anonymous first — it's free and frequently works before any exploit.
- SNMP community
public/privateand defaults are the quiet win people skip. - Confirm a CVE actually matches the exact version; wrong minor version = wasted exploit.
Verify success
Access or credentials from a service (share contents, LDAP users, a DB login), or confirmed exploitation of a versioned CVE — feeding foothold/privesc.
References
Service-enum references (HackTricks, 0xdf); netexec wiki; GTFOBins/searchsploit.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
network-service-attacks- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · microsoft
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infraconnect
Skill · composiohq
More in Databases & dataanalytics
Skill · coreyhaines31
More in Databases & dataazure-kusto
Skill · microsoft
More in Databases & dataagentic-os
Skill · affaan-m
More in Databases & data