CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is performing an internal network assessment. They have compromised a Linux server and want to identify which services are actively listening on TCP and UDP ports, along with the associated process IDs (PIDs) and their corresponding program names. This information will help them understand the server's function and potential pivot points. Which command would provide the most comprehensive details for this task?
- Aps aux
- Bnetstat -r
- Clsof -i
- Dss -tulnp
Show answer & explanationAnswer & explanation
Correct answer: D. ss -tulnp
The `ss -tulnp` command in Linux is a modern and efficient tool to display all listening TCP (`-t`) and UDP (`-u`) sockets, numerically (`-n`), along with the process ID (`-p`) and program name (`-l`). This provides a comprehensive overview of network services.
Why the other options are wrong
- A. ps aux lists all running processes, but does not directly show network listening ports or their protocols.
- B. netstat -r shows the kernel routing table, not listening services and their processes.
- C. lsof -i lists all open files and network connections by processes, but 'ss' is more direct and comprehensive for listening services with PIDs and program names.
ss -tulnp
A command-line utility in Linux used to display socket statistics, including all listening TCP and UDP ports, their numerical addresses, associated process IDs, and program names.
- Replaces or augments `netstat` in modern Linux systems.
- `-t`: TCP sockets, `-u`: UDP sockets, `-l`: listening sockets.
- `-n`: Numerical addresses, `-p`: Process ID/name.
- Excellent for service enumeration and understanding network activity.
Memory trick: SS Shows TCP/UDP Listening Processes