Nmap Development mailing list archives

Re: Last call for smtp-open-relay.nse - help needed


From: Duarte Silva <duartejcsilva () gmail com>
Date: Tue, 2 Mar 2010 21:34:24 +0000

They are running the qmail SMTP server
(http://pobox.com/~djb/qmail.html). The script end result is the
following

25/tcp open  smtp    syn-ack
| smtp-enum-users:
|_  ERROR: Couldn't find any account names

The smtp server does not implement EXPN but it does implement VRFY.
The VRFY always return

252 send some mail, i'll try my best..

On Tue, Mar 2, 2010 at 9:11 PM, David Fifield <david () bamsoftware com> wrote:
On Tue, Mar 02, 2010 at 08:36:48PM +0000, Duarte Silva wrote:
Okay, this is a good idea. It's not a problem if it's not supported on
lots of servers, especially if the script can realize it quickly and not
continue. What server are you testing the script against?

I was testing against my ISP server and the one under the
bamsoftware.com domain (sorry 'bout that :P). The script will stop
querying the SMTP server if authentication is enforced, or if the
commands used aren't implemented (VRFY and EXPN).

Do you get any results from the ISP server? Can you tell what software
it's running?

David Fifield

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: