CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard

A penetration tester is performing internal network reconnaissance. They have compromised a low-privilege user account on a Windows domain and want to identify other active hosts on the network segment. They are restricted from installing new tools and prefer a method that leverages built-in Windows commands. Which of the following commands would be most effective for discovering other active hosts?

  1. Aping -t <subnet_broadcast_address>
  2. Bnetstat -ano
  3. Cnbtstat -A <ip_address>
  4. Dfor /L %i in (1,1,254) do @ping -n 1 -w 100 <subnet_prefix>.%i | findstr /i "Reply from"
Show answer & explanation

Correct answer: D. for /L %i in (1,1,254) do @ping -n 1 -w 100 <subnet_prefix>.%i | findstr /i "Reply from"

This command uses a 'for' loop to iterate through all possible IP addresses in a /24 subnet, sending a single ping to each. The 'findstr' command filters the output to show only responses, effectively identifying active hosts using built-in Windows commands.

Why the other options are wrong

  • A. Pinging the broadcast address can be blocked by firewalls or routers and may not provide individual host responses reliably.
  • B. netstat -ano shows active network connections on the local machine, not other hosts on the network.
  • C. nbtstat -A queries a specific IP for NetBIOS information, not for scanning a range of hosts.

Windows Command Line Host Discovery

Leveraging native Windows commands like 'ping' and 'for' loops to discover active hosts on a local network segment without installing third-party tools.

  • Utilizes 'ping' for ICMP echo requests.
  • 'for' loops enable iterating through IP ranges.
  • 'findstr' can filter output for successful replies.
  • Useful for internal reconnaissance with limited privileges.

Memory trick: Windows commands reveal network neighbors.

More Reconnaissance and Enumeration questions