Nmap Development mailing list archives
Re: Last call for smtp-open-relay.nse - help needed
From: Duarte Silva <duartejcsilva () gmail com>
Date: Tue, 2 Mar 2010 20:36:48 +0000
Okay, this is a good idea. It's not a problem if it's not supported on lots of servers, especially if the script can realize it quickly and not continue. What server are you testing the script against?
I was testing against my ISP server and the one under the bamsoftware.com domain (sorry 'bout that :P). The script will stop querying the SMTP server if authentication is enforced, or if the commands used aren't implemented (VRFY and EXPN). On Mon, Mar 1, 2010 at 11:43 PM, David Fifield <david () bamsoftware com> wrote:
On Sat, Feb 27, 2010 at 06:37:46PM +0000, Duarte Silva wrote:I made the changes necessary in order to make it clearer. Now the script will handle TIMEOUT, EOF, and ERROR conditions from receive_lines function and return the message accordingly. Tested against the same SMTP server and it outputted the following.25/tcp open smtp syn-ack Exim smtpd 4.69 | smtp-open-relay: |_ ERROR: Failed to issue RSET command (connection closed)There are some other changes: + More information in the script description * If some combinations were already found before an error, the script will report themThanks, these are committed now.I also developed a new script that will try to enumerate the users in a SMTP server using the VRFY or the EXPN command (using the usernames.lst). If this is found to be useful since it seem that there aren't many servers that allow those commands.Okay, this is a good idea. It's not a problem if it's not supported on lots of servers, especially if the script can realize it quickly and not continue. What server are you testing the script against? David Fifield
_______________________________________________ Sent through the nmap-dev mailing list http://cgi.insecure.org/mailman/listinfo/nmap-dev Archived at http://seclists.org/nmap-dev/
Current thread:
- Re: Last call for smtp-open-relay.nse - help needed, (continued)
- Re: Last call for smtp-open-relay.nse - help needed Duarte Silva (Feb 21)
- Re: Last call for smtp-open-relay.nse - help needed Duarte Silva (Feb 21)
- Re: Last call for smtp-open-relay.nse - help needed David Fifield (Feb 22)
- Re: Last call for smtp-open-relay.nse - help needed Duarte Silva (Feb 22)
- Re: Last call for smtp-open-relay.nse - help needed Duarte Silva (Feb 27)
- Re: Last call for smtp-open-relay.nse - help needed Arturo 'Buanzo' Busleiman (Feb 27)
- Re: Last call for smtp-open-relay.nse - help needed Duarte Silva (Feb 27)
- Re: Last call for smtp-open-relay.nse - help needed David Fifield (Mar 01)
- Re: Last call for smtp-open-relay.nse - help needed Ron (Mar 01)
- Message not available
- Message not available
- Re: Last call for smtp-open-relay.nse - help needed Duarte Silva (Mar 02)
- Re: Last call for smtp-open-relay.nse - help needed Duarte Silva (Mar 02)
- Re: Last call for smtp-open-relay.nse - help needed David Fifield (Mar 02)
- Re: Last call for smtp-open-relay.nse - help needed Duarte Silva (Mar 02)
- Re: Last call for smtp-open-relay.nse - help needed David Fifield (Mar 02)
- Re: Last call for smtp-open-relay.nse - help needed Ron (Mar 02)
- Re: Last call for smtp-open-relay.nse - help needed Duarte Silva (Mar 02)
- Re: Last call for smtp-open-relay.nse - help needed Ron (Mar 02)
- Re: Last call for smtp-open-relay.nse - help needed David Fifield (Mar 02)
- Re: Last call for smtp-open-relay.nse - help needed Duarte Silva (Mar 03)
- Re: Last call for smtp-open-relay.nse - help needed Ron (Mar 03)
- Re: Last call for smtp-open-relay.nse - help needed Fyodor (Mar 05)