Remote-access services exist to control a system from elsewhere, so compromising one is, by definition, a direct route to a shell, a desktop, or the internal network behind a gateway. That makes them among the most valuable targets on a network and the leading initial-access vector in practice. The services differ in protocol and era but share a recurring set of aspects: enumeration and fingerprinting, authentication (credentials, keys, trust), transport cryptography, protocol or implementation flaws, and abuse of the access once gained. The area is organised by service, with those aspects under each.
Finding remote-access services#
# one sweep across the common remote-access ports
nmap -sV -p22,23,512,513,514,3389,5900-5902,5985,5986,443,500,1723,623 <target>
nmap -sU -p500,4500,623 <target> # IKE/IPsec and IPMI (UDP)
# 22 SSH 23 Telnet 512-514 r-cmds 3389 RDP 5900+ VNC 5985/6 WinRM
# 443 SSL-VPN/portal 500/4500 IPsec 1723 PPTP 623 IPMI/BMC
Subtopics#
- SSH: the encrypted remote shell, keys, crypto, trust, and tunnelling.
- RDP: the Windows remote desktop, NLA, pre-auth RCE, and session abuse.
- VNC: the RFB desktop, weak auth and cleartext.
- Telnet: the cleartext terminal and telnetd flaws.
- Shell protocols: the Berkeley r-commands and host trust.
- VPN: remote-access gateways, protocols, and SSL-VPN appliance exploits.
- WinRM: Windows Remote Management and PowerShell Remoting.
- Out-of-band management: BMCs, IPMI, iDRAC/iLO, and Redfish.
- Desktop software: third-party remote-desktop tools.