CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard
A penetration tester has gained access to a Linux system within a client's network. To understand the network connections established by the system and identify listening services, which command would be most effective for listing all active network connections and listening ports, including the associated process IDs and names?
- Ass -antp
- Bnetstat -tulnp
- Clsof -i
- Dip a
Show answer & explanationAnswer & explanation
Correct answer: B. netstat -tulnp
The `netstat -tulnp` command is a classic and highly effective way to list all TCP and UDP listening ports (`-t`, `-u`, `-l`), active connections, numeric addresses (`-n`), and crucially, the associated process ID and program name (`-p`) on a Linux system.
Why the other options are wrong
- A. `ss -antp` is a newer, faster alternative to netstat, displaying similar information including TCP (`-a`), numeric (`-n`), and process (`-p`), but `netstat -tulnp` is generally more familiar and widely available on older systems, and specifically asks for 'listening services' which `-l` covers directly.
- C. `lsof -i` lists open files (including network sockets) by processes, filtered by internet connections. While powerful, `netstat` is more direct and commonly associated with service and port enumeration.
- D. `ip a` displays network interface information (IP addresses, MAC addresses) but not active connections or listening ports.
netstat -tulnp
A Linux command combination used to display all active network connections and listening ports for both TCP and UDP, including the associated process ID and program name.
- Displays TCP (-t) and UDP (-u) connections.
- Shows listening sockets (-l).
- Includes numeric addresses (-n) and process info (-p).
- Essential for internal network reconnaissance.
Memory trick: Netstat shows Network STatus, including Processes and Listening ports.