Re: Sniffing packets between Outlook and Exchange

From: Jeff King (peff-pentest@fenris.cc)
Date: 12/12/01


Date: Tue, 11 Dec 2001 19:06:27 -0500 (EST)
From: Jeff King <peff-pentest@fenris.cc>
To: "'pen-test@securityfocus.com'" <pen-test@securityfocus.com>

On Tue, 11 Dec 2001, Harrington, Chris wrote:

> In an environment with Outlook 2000 acting as an Exchange client (no POP),
> is it possible to sniff the email traffic between the them?? If so, are
> there any resources on preventing this?

I looked into this several years ago. IIRC, Outlook->Exchange traffic is
tunneled through an SMB named pipe. It gets user authentication at the
SMB level. It may also get encryption services there; I don't know.

You might try running a sniffer against your box as you submit or read a
message then grep the results for the partial contents of the message.
You can't prove that it's unsniffable by failing, but you can certainly
prove that it's sniffable by succeeding. :)

-Jeff

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: ettercap help
    ... Anyways have never tried Ettercap for VNC. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: Wardialing
    ... >>> achieving the connection with the modem. ... >>This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • RE: How to Tackle the Legal Tangle?
    ... How to Tackle the Legal Tangle? ... >This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • RE: CFM SQL injection
    ... You should better use union or alike get unauthorized data from the ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: ettercap help
    ... > I can get it to sniff telnet, ftp, pop, smb, but no vnc. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)