CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester has gained initial access to a Linux server and wants to identify all open network connections and listening services to understand the network footprint of the compromised system. Which command provides the most comprehensive view of active TCP and UDP connections, along with the associated programs and their PIDs?

  1. Anetstat -tulnp
  2. Blsof -i
  3. Cip a
  4. Dss -antp
Show answer & explanation

Correct answer: A. netstat -tulnp

The `netstat -tulnp` command is highly effective on Linux for displaying listening and established TCP and UDP connections (`-t` for TCP, `-u` for UDP, `-l` for listening, `-n` for numeric addresses/ports, and `-p` for program/PID). This provides a comprehensive overview of network activity.

Why the other options are wrong

  • B. `lsof -i` lists open files related to network connections, which can be verbose and less direct for a summary of services than netstat.
  • C. `ip a` displays network interface information and IP addresses, not active connections or listening services.
  • D. `ss -antp` is a more modern alternative to netstat, providing similar information but `netstat -tulnp` is often taught as the comprehensive option.

netstat -tulnp

A Linux command used to display active network connections, listening ports, routing tables, and network interface statistics. The `-tulnp` flags specifically show TCP and UDP connections, listening sockets, numeric addresses/ports, and the associated program names and PIDs.

  • `-t`: Show TCP connections.
  • `-u`: Show UDP connections.
  • `-l`: Show only listening sockets.
  • `-n`: Display numeric addresses and port numbers.
  • `-p`: Display the PID and name of the program owning the socket (requires root).
  • Comprehensive for local network footprint analysis.

Memory trick: Netstat's 'tulnp' is like a network x-ray for your Linux box.

More Reconnaissance and Enumeration questions