CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard
A penetration tester is performing internal network reconnaissance. They have compromised a low-privilege user account on a Windows domain and want to identify other active hosts on the network segment. They are restricted from installing new tools and prefer a method that leverages built-in Windows commands. Which of the following commands would be most effective for discovering other active hosts?
- Aping -t <subnet_broadcast_address>
- Bnetstat -ano
- Cnbtstat -A <ip_address>
- Dfor /L %i in (1,1,254) do @ping -n 1 -w 100 <subnet_prefix>.%i | findstr /i "Reply from"
Show answer & explanationAnswer & explanation
Correct answer: D. for /L %i in (1,1,254) do @ping -n 1 -w 100 <subnet_prefix>.%i | findstr /i "Reply from"
This command uses a 'for' loop to iterate through all possible IP addresses in a /24 subnet, sending a single ping to each. The 'findstr' command filters the output to show only responses, effectively identifying active hosts using built-in Windows commands.
Why the other options are wrong
- A. Pinging the broadcast address can be blocked by firewalls or routers and may not provide individual host responses reliably.
- B. netstat -ano shows active network connections on the local machine, not other hosts on the network.
- C. nbtstat -A queries a specific IP for NetBIOS information, not for scanning a range of hosts.
Windows Command Line Host Discovery
Leveraging native Windows commands like 'ping' and 'for' loops to discover active hosts on a local network segment without installing third-party tools.
- Utilizes 'ping' for ICMP echo requests.
- 'for' loops enable iterating through IP ranges.
- 'findstr' can filter output for successful replies.
- Useful for internal reconnaissance with limited privileges.
Memory trick: Windows commands reveal network neighbors.