In order to use Ncrack, we can take the information we have been gathering so far on live systems, port scans, and usernames to get things started:
- Find a live system.
- Look for ports that have a service running on them that Ncrack supports.
- Perform a banner grab against the port using telnet or your banner-grabbing tool of choice (such as nmap) to fingerprint the service.
- Use any usernames, such as those you gathered from SMTP enumeration, and save them to a text file. Save the file with a name you can remember, such as usernames.txt.
- Create a second text file with the passwords you want to try. You can alternatively download this file from the internet by locating one with a simple search for password lists ...