![]() |
|
Banner Grabbing(FTP, SSH, SMTP, and more) - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: Banner Grabbing(FTP, SSH, SMTP, and more) (/Thread-Banner-Grabbing-FTP-SSH-SMTP-and-more) Pages:
1
2
|
Banner Grabbing(FTP, SSH, SMTP, and more) - mls577 - 06-11-2013 *Not sure if this has been posted before but with a quick search I didn't find anything. This is a post from another forum but is my work. Banner Grabbing If you've never heard of banner grabbing before, then I'll explain it for you simply. Banner grabbing is a technique that you can use to get information about what a target is running(service wise). After you discover what ports are open and being used, you may use this technique to find out what kind of software is being run and what version of that software. In this tutorial we are specifically focusing on 3 services: ftp, ssh, and smtp. The reason why we are only mentioning these three services is because banner grabbing these three are the same and don't change in technique at all, though this technique can be used as a part of others. We will be using telnet to do our banner grabbing because it is already installed and available on most OS's.Alternatively you can use netcat or similar if you prefer. Anyway let's get to it. We will need to open up a console and type the following: Code: telnet <host> <port>FTP An ftp example would be: Code: telnet 209.197.248.xx 21which gives us the output: ![]() Our banner: Code: 220 ProFTPD 1.3.3d Server (ProFTPD) [209.197.248.xx]SSH An ssh example would be: Code: telnet 174.36.209.xx 22![]() Our banner: Code: SSH-2.0-OpenSSH_5.5p1 Debian-6+squeeze1SMTP An smtp example would be: Code: telnet 206.103.2.xx 25which gives us the output: ![]() Our banner: Code: 220 xxxxxxxxxxxxx Microsoft ESMTP MAIL Service, Version: 6.0.3790.4675 ready at Mon, 18 Jun 2012 20:28:44 -0400I made a simple python script to do this aswell, as an alternative to telnet Spoiler:Code: #!/usr/bin/env/python3.1
#mls577
#haxme, #suidrewt
import sys, socket #module imports
if(len(sys.argv) == 3): #argument length check
host = sys.argv[1] #host
port = sys.argv[2] #port
#create socket
s = socket.socket()
try:
connect = s.connect((host, int(port))) #connect to the host
banner = s.recv(1024) #recieve the banner
print(banner) #print the output
s.close() #close socket
except socket.error:
s.close() #close socket
print("socket error")
else:
print("usage: program.py <host> <port>")*As a side note you should know that the accuracy of your results depends on the host, most administrators will manipulate their banner to throw you off. RE: Banner Grabbing(FTP, SSH, SMTP, and more) - deb0and - 07-13-2013 Guys you should be using netcat to do your banner grabbing for obvious reasons. Don't forget you can wrap netcat using something like stunnel so you can communicate with ssl. for example if you use telnet or netcat for that reason to try and grab a banner on port HTTPS 443 it will not be able to communicate because it wont understand the request. I've seen a lot of networks where they have ftp, IMAP etc all ssl encrypted. Learn how to use stunnel. Also it's useful to pipe data out of a network, wraps up the data so it will bypass ips & packet inspection etc, obviously if your going to pipe data out on a stupid port number it will get flagged, but we all know all networks/businesses firewalls have port 443 outbound. Just use what they give you
RE: Banner Grabbing(FTP, SSH, SMTP, and more) - deb0and - 07-13-2013 Guys you should be using netcat to do your banner grabbing for obvious reasons. Don't forget you can wrap netcat using something like stunnel so you can communicate with ssl. for example if you use telnet or netcat for that reason to try and grab a banner on port HTTPS 443 it will not be able to communicate because it wont understand the request. I've seen a lot of networks where they have ftp, IMAP etc all ssl encrypted. Learn how to use stunnel. Also it's useful to pipe data out of a network, wraps up the data so it will bypass ips & packet inspection etc, obviously if your going to pipe data out on a stupid port number it will get flagged, but we all know all networks/businesses firewalls have port 443 outbound. Just use what they give you
RE: Banner Grabbing(FTP, SSH, SMTP, and more) - lady_godiva - 07-21-2013 Agreed, netcat nowadays is much better than telnet, learning how to use it should be a must. RE: Banner Grabbing(FTP, SSH, SMTP, and more) - lady_godiva - 07-21-2013 Agreed, netcat nowadays is much better than telnet, learning how to use it should be a must. RE: Banner Grabbing(FTP, SSH, SMTP, and more) - lady_godiva - 07-21-2013 Agreed, netcat nowadays is much better than telnet, learning how to use it should be a must. RE: Banner Grabbing(FTP, SSH, SMTP, and more) - Vip3r - 08-24-2014 When i typed 'telnet <ip> <port>', I got the following message: HTTP/1.0 400 Bad request Cache-Control: no-cache Connection: close Content-Type: text/html <html><body><h1>400 Bad request</h1> Your browser sent an invalid request. </body> </html> Can anyone please explain me, why is not it working? RE: Banner Grabbing(FTP, SSH, SMTP, and more) - Vip3r - 08-24-2014 When i typed 'telnet <ip> <port>', I got the following message: HTTP/1.0 400 Bad request Cache-Control: no-cache Connection: close Content-Type: text/html <html><body><h1>400 Bad request</h1> Your browser sent an invalid request. </body> </html> Can anyone please explain me, why is not it working? RE: Banner Grabbing(FTP, SSH, SMTP, and more) - mls577 - 08-24-2014 (08-24-2014, 06:52 PM)Vip3r Wrote: When i typed 'telnet <ip> <port>', I got the following message: HTTP is different, I used the above as examples because they were all similar. You'd have to follow up with a GET or HEAD request. I google for something simple for you: http://wcosughacking.blogspot.com/2011/06/banner-grabbing.html If this fails there are other methods such as: http://www.net-square.com/httprint_paper.html RE: Banner Grabbing(FTP, SSH, SMTP, and more) - mls577 - 08-24-2014 (08-24-2014, 06:52 PM)Vip3r Wrote: When i typed 'telnet <ip> <port>', I got the following message: HTTP is different, I used the above as examples because they were all similar. You'd have to follow up with a GET or HEAD request. I google for something simple for you: http://wcosughacking.blogspot.com/2011/06/banner-grabbing.html If this fails there are other methods such as: http://www.net-square.com/httprint_paper.html |