Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


How should I interpret this nmap suggestion? filter_list
Author
Message
How should I interpret this nmap suggestion? #1
So Ive been attempting to access a large site and after a few nmap scans I received this:

Code:
110/tcp open pop3 Courier pop3d |_pop3-capabilities: USER IMPLEMENTATION(Courier Mail Server) UIDL APOP TOP OK(K Here s what I can do) STLS PIPELINING LOGIN-DELAY(10) SASL(LOGIN CRAM-MD5 CRAM-SHA1 CRAM-SHA256 PLAIN)

When I run it I recieve:

Code:
+OK Hello there. <22065.1401091743@localhost.localdomain> STLS PIPELINING LOGIN-DELAY(10) SASL(LOGIN CRAM-MD5 CRAM-SHA1 CRAM-SHA256 PLAIN) +OK Begin SSL/TLS negotiation now.

So this suggests I have access over SSL but what commands should I run and it all seemed a little too easy.

Thanks in advance!

Reply

RE: How should I interpret this nmap suggestion? #2
lol. lucky you. I havent seen something that easy in a while. On the other hand, it could potentially be a trap

Reply

RE: How should I interpret this nmap suggestion? #3
(05-27-2014, 04:57 AM)ICE_ Wrote: lol. lucky you. I havent seen something that easy in a while. On the other hand, it could potentially be a trap

The site is large with thousands of users although it has a poorly made gui and other scans and probing shows that it basically relies entirely on CloudFlare.

Can you link me to a page on SSL Querying or whatever the specified term is? I cant seem to find anything.

Reply

RE: How should I interpret this nmap suggestion? #4
(05-27-2014, 06:30 AM)antlers Wrote: The site is large with thousands of users although it has a poorly made gui and other scans and probing shows that it basically relies entirely on CloudFlare.

Can you link me to a page on SSL Querying or whatever the specified term is? I cant seem to find anything.

SSL is just a method of encryption, you're still just sending HTML (or whatever the case may be), I think in this case you have an SSL encrypted remote command prompt, terminal, or similar. Just treat it like you would a normal command prompt?
[Image: jWSyE88.png]

Reply

RE: How should I interpret this nmap suggestion? #5
(05-27-2014, 07:29 AM)3SidedSquare Wrote: SSL is just a method of encryption, you're still just sending HTML (or whatever the case may be), I think in this case you have an SSL encrypted remote command prompt, terminal, or similar. Just treat it like you would a normal command prompt?

Code:
+OK Hello there. <27961.1401172755@localhost.localdomain> STLS PIPELINING LOGIN-DELAY(10) SASL(LOGIN CRAM-MD5 CRAM-SHA1 CRAM-SHA256 PLAIN) +OK Begin SSL/TLS negotiation now. echo Testing. -ERR STARTTLS failed: couriertls: accept: error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number -ERR Invalid command. ls -ERR Invalid command. help -ERR Invalid command. quit +OK Better luck next time.

Reply

RE: How should I interpret this nmap suggestion? #6
(05-27-2014, 06:30 AM)antlers Wrote: The site is large with thousands of users although it has a poorly made gui and other scans and probing shows that it basically relies entirely on CloudFlare.

Can you link me to a page on SSL Querying or whatever the specified term is? I cant seem to find anything.

sounds like you've really hit the jackpot with this one buddy.
you should check some of the packets through wireshark, who knows, they might be dropping info over clear text or null encryption. Also, this is probably irrelevant by now but a heart bleed test wouldn't hurt.

As for the 'SSL Querying', SSL is basically just encrypted HTML. The site is hiding something (command prompt, terminal, etc.) behind a wall (SSL).
if you just look up something like 'SSL checkpoints' and see if their specs match up with the checkpoints (MD5 certs, short certs, no cleartext, etc. etc. etc.) then you'll be good, if one of those turns up false (not there) then you've probably found a decent vuln.

Have fun, stay frosty, and don't get caught.

Edit: I forgot to add, always read error reports! red lines are the best!

Reply

RE: How should I interpret this nmap suggestion? #7
(05-27-2014, 11:41 PM)ICE_ Wrote: sounds like you've really hit the jackpot with this one buddy.
you should check some of the packets through wireshark, who knows, they might be dropping info over clear text or null encryption. Also, this is probably irrelevant by now but a heart bleed test wouldn't hurt.

As for the 'SSL Querying', SSL is basically just encrypted HTML. The site is hiding something (command prompt, terminal, etc.) behind a wall (SSL).
if you just look up something like 'SSL checkpoints' and see if their specs match up with the checkpoints (MD5 certs, short certs, no cleartext, etc. etc. etc.) then you'll be good, if one of those turns up false (not there) then you've probably found a decent vuln.

Have fun, stay frosty, and don't get caught.

Edit: I forgot to add, always read error reports! red lines are the best!

A heartbleed test came up false positive.

Could you perhaps emphasize what I have actually done I feel like I am stumbling about in the dark here. Wireshark results merely echoed what I could see from the netcat connection.

- How do I find the specs?
- How can I log SSL data through this?

Once again thanks.

Reply

RE: How should I interpret this nmap suggestion? #8
No no no no no.
Code:
STLS PIPELINING LOGIN-DELAY(10) SASL(LOGIN CRAM-MD5 CRAM-SHA1 CRAM-SHA256 PLAIN)
These are POP3 commands that you can use without having to login to the POP3 service. You can attempt logging in by doing something along the lines of:
Code:
telnet x.x.x.x 110 USER someusername PASS somepasswd
If you do not want to login, and instead want to try using these commands, simply type them into the prompt you are presented with. You won't have any system command capabilities, as you are interacting with the pop3 service, not the actual server itself. However, if you manage to break into the pop3 service, you should be able to gain a lot of really good info about the target server that you could leverage against some other attack vector.

Reply

RE: How should I interpret this nmap suggestion? #9
(05-28-2014, 02:34 PM)m0rph Wrote: No no no no no.
Code:
STLS PIPELINING LOGIN-DELAY(10) SASL(LOGIN CRAM-MD5 CRAM-SHA1 CRAM-SHA256 PLAIN)
These are POP3 commands that you can use without having to login to the POP3 service. You can attempt logging in by doing something along the lines of:
Code:
telnet x.x.x.x 110 USER someusername PASS somepasswd
If you do not want to login, and instead want to try using these commands, simply type them into the prompt you are presented with. You won't have any system command capabilities, as you are interacting with the pop3 service, not the actual server itself. However, if you manage to break into the pop3 service, you should be able to gain a lot of really good info about the target server that you could leverage against some other attack vector.

So its effectively useless? oh well.

Reply