Exhange 2003

From: Deniz CEVIK (deniz_at_edizayn.com.tr)
Date: 03/02/04

  • Next message: Alfred Huger: "New Articles @ SecurityFocus"
    To: <pen-test@securityfocus.com>
    Date: Tue, 2 Mar 2004 16:29:49 +0200
    
    

    Hi All,

    While we are testing our customer network, we faced with strange problem. We
    are testing exchange 2003 server externally. When we controlled open
    services with port scan, I saw that only two ports (25 and 100) are shown as
    open. Before I run the portscan, I have controlled the server with "nbtstat"
    command of windows. It returned error messages as below.

    nbtstat -A EXCH_IP

    Local Area Connection:
    Node IpAddress: [MY_MACHINE] Scope Id: []

        Host not found.

    After the port scan is finished, in order to see the banner information of
    mail server, I opened the connection to port 25 using telnet command (telnet
    EXCH_IP 25). Same time when I run "nbtstat -A" command from another window
    by mistake and I saw that below output.

    nbtstat -A EXCH_IP

    Local Area Connection:
    Node IpAddress: [MY_MACHINE] Scope Id: []

               NetBIOS Remote Machine Name Table

           Name Type Status
        ---------------------------------------------
        HADXM <1F> UNIQUE Registered
        HADXM <00> UNIQUE Registered
        HADXM <20> UNIQUE Registered
        EXCHANGE <00> GROUP Registered
        EXCHANGE <1C> GROUP Registered
        EXCHANGE <1B> UNIQUE Registered
        EXCHANGE <1E> GROUP Registered
        HADXM <03> UNIQUE Registered
        ADMINISTRATOR <03> UNIQUE Registered
        EXCHANGE <1D> UNIQUE Registered
        ..__MSBROWSE__. <01> GROUP Registered
        HADXM <6A> UNIQUE Registered
        HADXM <87> UNIQUE Registered

        MAC Address = MAC_ADDRESS_OF_EXCHANGE

    If there isn't any connection to open port of the server you can't see this
    nbtstat outputs.

    Has any body faced with same situations before?

    BR

    ---------------------------------------------------------------------------
    Free 30-day trial: firewall with virus/spam protection, URL filtering, VPN,
    wireless security

    Protect your network against hackers, viruses, spam and other risks with Astaro
    Security Linux, the comprehensive security solution that combines six
    applications in one software solution for ease of use and lower total cost of
    ownership.

    Download your free trial at
    http://www.securityfocus.com/sponsor/Astaro_pen-test_040201
    ----------------------------------------------------------------------------


  • Next message: Alfred Huger: "New Articles @ SecurityFocus"

    Relevant Pages

    • RE: Exchange 2003
      ... if this is a production server, ... cards, doing an nbtstat, then restarting them and doing it again. ... without exchange 2003 on it. ... # Local Area Connection: ...
      (Pen-Test)
    • RE: Exhange 2003
      ... it will talk to port ... hence the nbtstat response. ... are testing exchange 2003 server externally. ... command of windows. ...
      (Pen-Test)
    • Re: Renamed server, cant connect...
      ... At the command prompt run nbtstat -RR and Ipconfig /registerdns. ... Windows Server 2003 Enterprise w/ SQL 2000 Enterprise On an AD domain ... Local Area Connection 2: ... I can ping, connect via TS. ...
      (microsoft.public.windows.server.networking)
    • Re: Renamed server, cant connect...
      ... if it was registering names which would indicate the server, ... should show at least port 445 tcp and probably port 139 tcp listening. ... Your nbtstat results indicate Local Area Connection 2. ...
      (microsoft.public.windows.server.networking)
    • RE: Some technical errors
      ... If the SMTP server is not running on port 25 TCP it is not a public ... Manager - Computer Assurance Services BDO Chartered Accountants & ...
      (Security-Basics)