Banner Grabbing(FTP, SSH, SMTP, and more) 06-11-2013, 06:50 AM
#1
*Not sure if this has been posted before but with a quick search I didn't find anything. This is a post from another forum but is my work.
Banner Grabbing
If you've never heard of banner grabbing before, then I'll explain it for you simply. Banner grabbing is a technique that you can use to get information about what a target is running(service wise). After you discover what ports are open and being used, you may use this technique to find out what kind of software is being run and what version of that software. In this tutorial we are specifically focusing on 3 services: ftp, ssh, and smtp. The reason why we are only mentioning these three services is because banner grabbing these three are the same and don't change in technique at all, though this technique can be used as a part of others. We will be using telnet to do our banner grabbing because it is already installed and available on most OS's.Alternatively you can use netcat or similar if you prefer. Anyway let's get to it.
We will need to open up a console and type the following:
FTP
An ftp example would be:
which gives us the output:
![[Image: ftpc.jpg]](http://img707.imageshack.us/img707/5287/ftpc.jpg)
Our banner:
SSH
An ssh example would be:
which gives us the output:
![[Image: sshtat.jpg]](http://img137.imageshack.us/img137/164/sshtat.jpg)
Our banner:
SMTP
An smtp example would be:
which gives us the output:
![[Image: smtp.jpg]](http://imageshack.us/a/img696/9531/smtp.jpg)
Our banner:
I made a simple python script to do this aswell, as an alternative to telnet
*As a side note you should know that the accuracy of your results depends on the host, most administrators will manipulate their banner to throw you off.
Banner Grabbing
If you've never heard of banner grabbing before, then I'll explain it for you simply. Banner grabbing is a technique that you can use to get information about what a target is running(service wise). After you discover what ports are open and being used, you may use this technique to find out what kind of software is being run and what version of that software. In this tutorial we are specifically focusing on 3 services: ftp, ssh, and smtp. The reason why we are only mentioning these three services is because banner grabbing these three are the same and don't change in technique at all, though this technique can be used as a part of others. We will be using telnet to do our banner grabbing because it is already installed and available on most OS's.Alternatively you can use netcat or similar if you prefer. Anyway let's get to it.
We will need to open up a console and type the following:
Code:
telnet <host> <port>FTP
An ftp example would be:
Code:
telnet 209.197.248.xx 21which gives us the output:
![[Image: ftpc.jpg]](http://img707.imageshack.us/img707/5287/ftpc.jpg)
Our banner:
Code:
220 ProFTPD 1.3.3d Server (ProFTPD) [209.197.248.xx]SSH
An ssh example would be:
Code:
telnet 174.36.209.xx 22![[Image: sshtat.jpg]](http://img137.imageshack.us/img137/164/sshtat.jpg)
Our banner:
Code:
SSH-2.0-OpenSSH_5.5p1 Debian-6+squeeze1SMTP
An smtp example would be:
Code:
telnet 206.103.2.xx 25which gives us the output:
![[Image: smtp.jpg]](http://imageshack.us/a/img696/9531/smtp.jpg)
Our banner:
Code:
220 xxxxxxxxxxxxx Microsoft ESMTP MAIL Service, Version: 6.0.3790.4675 ready at Mon, 18 Jun 2012 20:28:44 -0400I made a simple python script to do this aswell, as an alternative to telnet
Spoiler:
Code:
#!/usr/bin/env/python3.1
#mls577
#haxme, #suidrewt
import sys, socket #module imports
if(len(sys.argv) == 3): #argument length check
host = sys.argv[1] #host
port = sys.argv[2] #port
#create socket
s = socket.socket()
try:
connect = s.connect((host, int(port))) #connect to the host
banner = s.recv(1024) #recieve the banner
print(banner) #print the output
s.close() #close socket
except socket.error:
s.close() #close socket
print("socket error")
else:
print("usage: program.py <host> <port>")*As a side note you should know that the accuracy of your results depends on the host, most administrators will manipulate their banner to throw you off.

![[+]](https://sinister.li/images/modern/collapse_collapsed.png)