Sinisterly
SMTP HACKING & USER-ENUMERATION - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.li/Forum-Tutorials)
+--- Thread: SMTP HACKING & USER-ENUMERATION (/Thread-SMTP-HACKING-USER-ENUMERATION)



SMTP HACKING & USER-ENUMERATION - LEGITimacy™ - 01-22-2013


Smtp-user-enum is a tool for enumerating OS-level user accounts on Solaris via the SMTP service (sendmail). Enumeration is performed by inspecting the responses to VRFY, EXPN and RCPT TO commands. It could be adapted to work against other vulnerable SMTP daemons, but this hasn’t been done as of v1.0.



INSTALLATION:



smtp-user-enum is just a stand alone PERL script, so installation is as simple as copying it to your path (e.g. /usr/local/bin). It has only been tested under Linux so far.

It depends on the following PERL modules which you may need to install first:

Socket
IO::Handle
IO::Select
IO::Socket::INET
Getopt::Std

If you have PERL installed, you should be able to install the modules from CPAN:

# perl -MCPAN -e shell
cpan> install Getopt::Std



DOWNLOAD LINK:
smtp_user_enum



MAIN MENU: (USAGE)


Usage: smtp-user-enum.pl [options] (-u username|-U file-of-usernames) (-t host|-T file-of-targets)

options are:
-m n Maximum number of processes (default: 5)
-M mode Method to use for username guessing EXPN, VRFY or RCPT (default: VRFY)
-u user Check if user exists on remote system
-f addr From email address to use for "RCPT TO" guessing (default: user@example.com)
-D dom Domain to append to supplied user list to make email addresses (Default: none)
Use this option when you want to guess valid email addresses instead of just usernames
e.g. "-D example.com" would guess foo@example.com, bar@example.com, etc. Instead of
simply the usernames foo and bar.
-U file File of usernames to check via smtp service
-t host Server host running smtp service
-T file File of hostnames running the smtp service
-p port TCP port on which smtp service runs (default: 25)
-d Debugging output
-t n Wait a maximum of n seconds for reply (default: 5)
-v Verbose
-h This help message



GETTING STARTED:




First lets make sure that our target is running an smtp server and port isnt filtered. Can be easily done with nmap or we could just do some banner grabbing with this command:

[root@hc:#] nc -v XX.XX.XX.XX 25

nc = netcat
-v = verbose
XX.XX.XX.XX = TARGET IP
25 = smtp port

##



STEP 2:


Once connected use VRFY or EXPN commands to verify for valid users or expand a mailing list. Don't forget though, most SMTP servers by default have VRFY and EXPN commands disabled by default. You will get hit by the server with an error code 502, either disabled or not implemented. So to get past this, most of the time we will be using the RCPT option.

After verifying which method we will be using for username or email guessing we will make a username list. This list can be used for both username and email enumeration. :yeye:




RUNNING SMTP_USER_ENUM:



EX. OF USERNAME ENUM USING RCPT TO COMMAND:

[root@hc:#] perl smtp-user-enum.pl -M RCPT -U users.txt -t 127.0.0.1

EX. OF EMAIL ADDRESS ENUM USING RCPT TO COMMAND:

[root@hc:#] perl -D hackcommunity.com -M RCPT -U users.txt -t 127.0.0.1

Notice the domain flag option in this command ^^ Needed when trying to enumerate email addresses.




EXAMPLE OF OUTPUT:


--
| Scan Information |
--

Mode .. VRFY
Worker Processes .. 5
Usernames file .. users.txt
Target count .. 1
Username count .. 47
Target TCP port .. 25
Query timeout .. 5 secs
Relay Server .. Not used

## Scan started at Sun Jan 21 18:01:50 2007 ##
root@10.0.0.1: Exists
bin@10.0.0.1: Exists
daemon@10.0.0.1: Exists
lp@10.0.0.1: Exists
adm@10.0.0.1: Exists
uucp@10.0.0.1: Exists
postmaster@10.0.0.1: Exists
nobody@10.0.0.1: Exists
ftp@10.0.0.1: Exists
## Scan completed at Sun Jan 21 18:01:50 2007 ##
9 results.

47 queries in 1 seconds (47.0 queries / sec)




Seems simple enough huh? :3 I just thought this was something interesting, and wanted to share with some of the guys who were unaware of this. This script is also available in BT. Has been to great use for me, with just a little trickery and thought its possible to gain a lot of information with this attack. I used this attack to help me with the hacking of one of MIT's SMTP server in the past and gathered the student mailing list consisting of around 12,000 email accounts. Very useful in my option.