Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Banner Grabbing(FTP, SSH, SMTP, and more) filter_list
Author
Message
Banner Grabbing(FTP, SSH, SMTP, and more) #1
*Not sure if this has been posted before but with a quick search I didn't find anything. This is a post from another forum but is my work.

Banner Grabbing

If you've never heard of banner grabbing before, then I'll explain it for you simply. Banner grabbing is a technique that you can use to get information about what a target is running(service wise). After you discover what ports are open and being used, you may use this technique to find out what kind of software is being run and what version of that software. In this tutorial we are specifically focusing on 3 services: ftp, ssh, and smtp. The reason why we are only mentioning these three services is because banner grabbing these three are the same and don't change in technique at all, though this technique can be used as a part of others. We will be using telnet to do our banner grabbing because it is already installed and available on most OS's.Alternatively you can use netcat or similar if you prefer. Anyway let's get to it.

We will need to open up a console and type the following:
Code:
telnet <host> <port>

FTP
An ftp example would be:
Code:
telnet 209.197.248.xx 21

which gives us the output:
[Image: ftpc.jpg]

Our banner:
Code:
220 ProFTPD 1.3.3d Server (ProFTPD) [209.197.248.xx]

SSH
An ssh example would be:
Code:
telnet 174.36.209.xx 22
which gives us the output:
[Image: sshtat.jpg]

Our banner:
Code:
SSH-2.0-OpenSSH_5.5p1 Debian-6+squeeze1


SMTP
An smtp example would be:
Code:
telnet 206.103.2.xx 25

which gives us the output:
[Image: smtp.jpg]

Our banner:
Code:
220 xxxxxxxxxxxxx Microsoft ESMTP MAIL Service, Version: 6.0.3790.4675 ready at Mon, 18 Jun 2012 20:28:44 -0400


I made a simple python script to do this aswell, as an alternative to telnet

Spoiler:
Code:
#!/usr/bin/env/python3.1 #mls577 #haxme, #suidrewt import sys, socket #module imports if(len(sys.argv) == 3): #argument length check host = sys.argv[1] #host port = sys.argv[2] #port #create socket s = socket.socket() try: connect = s.connect((host, int(port))) #connect to the host banner = s.recv(1024) #recieve the banner print(banner) #print the output s.close() #close socket except socket.error: s.close() #close socket print("socket error") else: print("usage: program.py <host> <port>")




*As a side note you should know that the accuracy of your results depends on the host, most administrators will manipulate their banner to throw you off.

Reply

RE: Banner Grabbing(FTP, SSH, SMTP, and more) #2
Guys you should be using netcat to do your banner grabbing for obvious reasons. Don't forget you can wrap netcat using something like stunnel so you can communicate with ssl. for example if you use telnet or netcat for that reason to try and grab a banner on port HTTPS 443 it will not be able to communicate because it wont understand the request.

I've seen a lot of networks where they have ftp, IMAP etc all ssl encrypted. Learn how to use stunnel.

Also it's useful to pipe data out of a network, wraps up the data so it will bypass ips & packet inspection etc, obviously if your going to pipe data out on a stupid port number it will get flagged, but we all know all networks/businesses firewalls have port 443 outbound. Just use what they give you Smile

Reply

RE: Banner Grabbing(FTP, SSH, SMTP, and more) #3
Guys you should be using netcat to do your banner grabbing for obvious reasons. Don't forget you can wrap netcat using something like stunnel so you can communicate with ssl. for example if you use telnet or netcat for that reason to try and grab a banner on port HTTPS 443 it will not be able to communicate because it wont understand the request.

I've seen a lot of networks where they have ftp, IMAP etc all ssl encrypted. Learn how to use stunnel.

Also it's useful to pipe data out of a network, wraps up the data so it will bypass ips & packet inspection etc, obviously if your going to pipe data out on a stupid port number it will get flagged, but we all know all networks/businesses firewalls have port 443 outbound. Just use what they give you Smile

Reply

RE: Banner Grabbing(FTP, SSH, SMTP, and more) #4
Agreed, netcat nowadays is much better than telnet, learning how to use it should be a must.
Everything is relative

Reply

RE: Banner Grabbing(FTP, SSH, SMTP, and more) #5
Agreed, netcat nowadays is much better than telnet, learning how to use it should be a must.
Everything is relative

Reply

RE: Banner Grabbing(FTP, SSH, SMTP, and more) #6
Agreed, netcat nowadays is much better than telnet, learning how to use it should be a must.
Everything is relative

Reply

RE: Banner Grabbing(FTP, SSH, SMTP, and more) #7
When i typed 'telnet <ip> <port>', I got the following message:
HTTP/1.0 400 Bad request
Cache-Control: no-cache
Connection: close
Content-Type: text/html

<html><body><h1>400 Bad request</h1>
Your browser sent an invalid request.
</body>
</html>
Can anyone please explain me, why is not it working?

Reply

RE: Banner Grabbing(FTP, SSH, SMTP, and more) #8
When i typed 'telnet <ip> <port>', I got the following message:
HTTP/1.0 400 Bad request
Cache-Control: no-cache
Connection: close
Content-Type: text/html

<html><body><h1>400 Bad request</h1>
Your browser sent an invalid request.
</body>
</html>
Can anyone please explain me, why is not it working?

Reply

RE: Banner Grabbing(FTP, SSH, SMTP, and more) #9
(08-24-2014, 06:52 PM)Vip3r Wrote: When i typed 'telnet <ip> <port>', I got the following message:
HTTP/1.0 400 Bad request
Cache-Control: no-cache
Connection: close
Content-Type: text/html

<html><body><h1>400 Bad request</h1>
Your browser sent an invalid request.
</body>
</html>
Can anyone please explain me, why is not it working?

HTTP is different, I used the above as examples because they were all similar. You'd have to follow up with a GET or HEAD request. I google for something simple for you: http://wcosughacking.blogspot.com/2011/0...bbing.html

If this fails there are other methods such as: http://www.net-square.com/httprint_paper.html
A Serious Newbies Guide to the Underground v3
http://www.hackcommunity.com/Thread-A-Se...-v3-Part-1

Reply

RE: Banner Grabbing(FTP, SSH, SMTP, and more) #10
(08-24-2014, 06:52 PM)Vip3r Wrote: When i typed 'telnet <ip> <port>', I got the following message:
HTTP/1.0 400 Bad request
Cache-Control: no-cache
Connection: close
Content-Type: text/html

<html><body><h1>400 Bad request</h1>
Your browser sent an invalid request.
</body>
</html>
Can anyone please explain me, why is not it working?

HTTP is different, I used the above as examples because they were all similar. You'd have to follow up with a GET or HEAD request. I google for something simple for you: http://wcosughacking.blogspot.com/2011/0...bbing.html

If this fails there are other methods such as: http://www.net-square.com/httprint_paper.html
A Serious Newbies Guide to the Underground v3
http://www.hackcommunity.com/Thread-A-Se...-v3-Part-1

Reply