Service detection

Identifying which remote-desktop product is present comes from two angles. On the network, the clients use characteristic ports, TeamViewer prefers TCP 5938 and falls back to 443/80, AnyDesk uses 7070 (and relays over 443), Splashtop and others use their own, so a targeted scan plus observation of connections to the vendor's relay infrastructure reveals the product. On a host you can inspect, the running processes, installed program files, and registry/app-data entries name the product precisely and point to where its configuration and any stored credentials live, which matters for unattended-password recovery.

bash
# network detection
nmap -p5938,7070,6568,443,80 -sV <target>
# connections to vendor relays indicate the product even when local ports are filtered
# host artefacts (Windows)
tasklist | findstr /i 'teamviewer anydesk splashtop logmein'
dir "%APPDATA%\AnyDesk" "%ProgramData%\TeamViewer" 2>nul

Exploitation notes#

  • The characteristic ports and relay destinations identify the product even behind NAT, because the client connects outward to the vendor relay; watch for those connections where inbound ports are filtered.
  • On a host, the product's app-data/registry location is also where its configuration and unattended credentials are stored, so service detection feeds unattended-access credential recovery.
  • Multiple tools are often installed (a managed one plus a user-installed one); enumerate all, as a forgotten or shadow install may be the weakest.
  • The identified product plus its version selects the authentication attack and the applicable product exploit.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more