CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester has gained access to a Linux system and needs to identify running services and their associated open ports to further enumerate the system. They are looking for a command that provides a comprehensive list of listening sockets and their corresponding processes. Which of the following commands would best achieve this goal?

  1. Aps aux
  2. Bss -antp
  3. Cnetstat -tulnp
  4. Dlsof -i
Show answer & explanation

Correct answer: C. netstat -tulnp

The 'netstat -tulnp' command is a classic and highly effective way to list all TCP (t) and UDP (u) listening (l) ports, show numeric addresses (n), and display the process ID (p) and program name associated with each socket.

Why the other options are wrong

  • A. ps aux lists all running processes but doesn't directly show open ports or listening sockets.
  • B. ss -antp is also a very good and often preferred modern alternative to netstat for showing socket statistics, including listening ports and processes. However, 'netstat -tulnp' is the more classic and widely recognized syntax that accomplishes the same, making it a strong contender and often expected answer in certifications.
  • D. lsof -i shows open files (including network sockets) and processes, but 'netstat -tulnp' is more commonly used and often more direct for listening ports.

netstat for Service Enumeration

The 'netstat' command with specific flags (e.g., -tulnp) is used on Linux systems to display network connections, routing tables, interface statistics, and most importantly, listening ports and the processes associated with them.

  • '-t' shows TCP connections.
  • '-u' shows UDP connections.
  • '-l' shows only listening sockets.
  • '-n' shows numeric addresses and port numbers.
  • '-p' shows the PID and program name for the socket.

Memory trick: Linux commands reveal open doors.

More Reconnaissance and Enumeration questions