![]() |
|
How should I interpret this nmap suggestion? - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Network Hacking (https://sinister.li/Forum-Network-Hacking) +--- Thread: How should I interpret this nmap suggestion? (/Thread-How-should-I-interpret-this-nmap-suggestion) |
How should I interpret this nmap suggestion? - superMAUS - 05-26-2014 So Ive been attempting to access a large site and after a few nmap scans I received this: Code: 110/tcp open pop3 Courier pop3d
|_pop3-capabilities: USER IMPLEMENTATION(Courier Mail Server) UIDL APOP TOP OK(K Here s what I can do) STLS PIPELINING LOGIN-DELAY(10) SASL(LOGIN CRAM-MD5 CRAM-SHA1 CRAM-SHA256 PLAIN)When I run it I recieve: Code: +OK Hello there. <22065.1401091743@localhost.localdomain>
STLS PIPELINING LOGIN-DELAY(10) SASL(LOGIN CRAM-MD5 CRAM-SHA1 CRAM-SHA256 PLAIN)
+OK Begin SSL/TLS negotiation now.So this suggests I have access over SSL but what commands should I run and it all seemed a little too easy. Thanks in advance! RE: How should I interpret this nmap suggestion? - ICE_ - 05-27-2014 lol. lucky you. I havent seen something that easy in a while. On the other hand, it could potentially be a trap RE: How should I interpret this nmap suggestion? - superMAUS - 05-27-2014 (05-27-2014, 04:57 AM)ICE_ Wrote: lol. lucky you. I havent seen something that easy in a while. On the other hand, it could potentially be a trap The site is large with thousands of users although it has a poorly made gui and other scans and probing shows that it basically relies entirely on CloudFlare. Can you link me to a page on SSL Querying or whatever the specified term is? I cant seem to find anything. RE: How should I interpret this nmap suggestion? - 3SidedSquare - 05-27-2014 (05-27-2014, 06:30 AM)antlers Wrote: The site is large with thousands of users although it has a poorly made gui and other scans and probing shows that it basically relies entirely on CloudFlare. SSL is just a method of encryption, you're still just sending HTML (or whatever the case may be), I think in this case you have an SSL encrypted remote command prompt, terminal, or similar. Just treat it like you would a normal command prompt? RE: How should I interpret this nmap suggestion? - superMAUS - 05-27-2014 (05-27-2014, 07:29 AM)3SidedSquare Wrote: SSL is just a method of encryption, you're still just sending HTML (or whatever the case may be), I think in this case you have an SSL encrypted remote command prompt, terminal, or similar. Just treat it like you would a normal command prompt? Code: +OK Hello there. <27961.1401172755@localhost.localdomain>
STLS PIPELINING LOGIN-DELAY(10) SASL(LOGIN CRAM-MD5 CRAM-SHA1 CRAM-SHA256 PLAIN)
+OK Begin SSL/TLS negotiation now.
echo Testing.
-ERR STARTTLS failed: couriertls: accept: error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
-ERR Invalid command.
ls
-ERR Invalid command.
help
-ERR Invalid command.
quit
+OK Better luck next time.RE: How should I interpret this nmap suggestion? - ICE_ - 05-27-2014 (05-27-2014, 06:30 AM)antlers Wrote: The site is large with thousands of users although it has a poorly made gui and other scans and probing shows that it basically relies entirely on CloudFlare. sounds like you've really hit the jackpot with this one buddy. you should check some of the packets through wireshark, who knows, they might be dropping info over clear text or null encryption. Also, this is probably irrelevant by now but a heart bleed test wouldn't hurt. As for the 'SSL Querying', SSL is basically just encrypted HTML. The site is hiding something (command prompt, terminal, etc.) behind a wall (SSL). if you just look up something like 'SSL checkpoints' and see if their specs match up with the checkpoints (MD5 certs, short certs, no cleartext, etc. etc. etc.) then you'll be good, if one of those turns up false (not there) then you've probably found a decent vuln. Have fun, stay frosty, and don't get caught. Edit: I forgot to add, always read error reports! red lines are the best! RE: How should I interpret this nmap suggestion? - superMAUS - 05-28-2014 (05-27-2014, 11:41 PM)ICE_ Wrote: sounds like you've really hit the jackpot with this one buddy. A heartbleed test came up false positive. Could you perhaps emphasize what I have actually done I feel like I am stumbling about in the dark here. Wireshark results merely echoed what I could see from the netcat connection. - How do I find the specs? - How can I log SSL data through this? Once again thanks. RE: How should I interpret this nmap suggestion? - m0rph - 05-28-2014 No no no no no. Code: STLS PIPELINING LOGIN-DELAY(10) SASL(LOGIN CRAM-MD5 CRAM-SHA1 CRAM-SHA256 PLAIN)Code: telnet x.x.x.x 110
USER someusername
PASS somepasswdRE: How should I interpret this nmap suggestion? - superMAUS - 05-28-2014 (05-28-2014, 02:34 PM)m0rph Wrote: No no no no no. So its effectively useless? oh well. |