RE: Service Identification

From: J. Oquendo (sil_at_politrix.org)
Date: 12/08/03

  • Next message: R. DuFresne: "RE: Service Identification"
    Date: Mon, 8 Dec 2003 14:47:23 -0500 (EST)
    To: pen-test@securityfocus.com
    
    

    Simplest answer would be to run an analyzer on the segment the machine is
    on to see what information (if any) is going through the port. Remember
    any program can be assigned to listen on any port, so just because you may
    see something such as telnet mapped to port 23, it doesn't mean telnet is
    indeed running on that port.

    One thing to note also is, if indeed telnet is running on the port, it may
    have been configured not to leak out information. In essence, anything can
    be running on those ports... e.g.:

    finger sil@kungfunix.net

    Don't be fooled by what you would see doing that finger. Everything is
    false, usernames, etal...

    $ grep finger /etc/inetd.conf
    #finger stream tcp6 nowait nobody /usr/sbin/in.fingerd in.fingerd
    finger stream tcp6 nowait nobody /export/c0t0d0s9/home/sil/./honey

    It's a perl listener that catches e-tards doing stupid things. Sometimes I
    configure my firewall to block out class ranges if I see multiple asinine
    port connections, but it's mainly there for my amusement.

    sil

    > I did try this. It was unable to identify the service. I contacted the
    > client and they stated these were indeed Telnet and SMTP but protected
    > by TCP wrappers.

    > Does this sound like the response I would get by a service protected by
    > TCP wrappers?

    > Thanks,
    > Bryan

    =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
    J. Oquendo
    GPG Key ID 0x51F9D78D
    Fingerprint 2A48 BA18 1851 4C99 CA22 0619 DB63 F2F7 51F9 D78D

    http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x51F9D78D

    sil @ politrix . org http://www.politrix.org
    sil @ infiltrated . net http://www.infiltrated.net

    "I watch gangster flicks and root for the bad guy
    and turn it off before it ends because the bad guy dies"
    50 Cents - 'Assassins'

    This is a farce confidential disclaimer intended to make you
    aware that even though this may be priveledged information,
    being it will become Google cache in the future, my original
    intentions of keeping this message restricted and/or private
    are thrown out the door. If you have received this e-mail in
    error, please enjoy this signature and destroy this message
    by dousing it in gasoline.

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: R. DuFresne: "RE: Service Identification"

    Relevant Pages

    • Re: Telnet port 25
      ... Subject: Telnet port 25 ... is the sole responsibility of the customer and depends on the customer's ... Configuring sendmail 8.11.0 for Anti-Relay ...
      (AIX-L)
    • Re: Suggestion for a lexical (login mode via TCPIP)
      ... Not sure of it is the right one to modify or to add another one, but it would be useful to be able to get information on whether the user us coming in via FTP, TELNET, etc. ... This would also allow a LOGIN.COM to check if someone is coming in through a secure/SSL port for instance. ... For the HP SSH server, it seems to be undefined. ... forget about the possibility of virtual terminals. ...
      (comp.os.vms)
    • Re: Cannot telnet to port 25 from Windows 2003 SBS server to itself
      ... XFOR: Telnet to Port 25 of IMC to Test IMC Communication: ... Microsoft is providing this information as a convenience to you. ... This newsgroup only focuses on SBS technical issues. ...
      (microsoft.public.windows.server.sbs)
    • RE: RWW fails from Internet
      ... on port 4125: Connect failed" when you telnet to 4125. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
      (microsoft.public.windows.server.sbs)
    • Re: Have to go to web site twice before it comes up
      ... I've ruled out Internet Explorer. ... Telnet does the same thing. ... it's not limited to port 80. ... running on top of it that will have to be re-set up (e.g. DNS, DHCP, AD, ...
      (microsoft.public.win2000.networking)