SMTP Information gathering
Lluis Mora, Neutralbit llmora@neutralbit.com
Black Hat Europe Amsterdam, NL // March 2007
SMTP Information gathering Lluis Mora, Neutralbit - - PowerPoint PPT Presentation
SMTP Information gathering Lluis Mora, Neutralbit llmora@neutralbit.com Black Hat Europe Amsterdam, NL // March 2007 sec urityinno vatio n Introduction E-mail is present in nearly every organization We all understand how it works
Black Hat Europe Amsterdam, NL // March 2007
www.neutralbit.com
SMTP Information gathering
www.neutralbit.com
SMTP Information gathering
www.neutralbit.com
SMTP Information gathering
www.neutralbit.com
SMTP Information gathering
Recei ved: f r om r el ay. exam pl e. com ( 201. 20. 51. 192) by neut r al bi t . com ( Post f i x) wi t h ESM TP i d 35B83500EC f or <l l m
neut r al bi t . com >; M
ay 2006 20: 26: 52 +0000 ( UTC)
www.neutralbit.com
SMTP Information gathering
www.neutralbit.com
SMTP Information gathering
Recei ved: f r om sm t p. exam pl e. com ( 6. Net - 45- 12- 192. dynam i cI P dynam i cI P. exam pl e. net [ 192. 12. 45. 6] ) by m ai l . exam pl e. or g ( Post f i x) wi t h ESM TP i d 0AB0E147B1 Recei ved: f r om sm t p. exam pl e. com ( sm t p. exam pl e. com [ 172. 18. 5. 21
by m
pl e. com ( 8. 11. 6/ 8. 11. 6) wi t h ESM TP i d i 82sokwi s; Recei ved: f r om vai o ( 172. 16. 1. 100
by sm t p. exam pl e. com ( Post f i x) wi t h ESM TP i d i 82shwk;
www.neutralbit.com
SMTP Information gathering
Recei ved: f r om m
pl e. com ( [ 195. 166. 192. 8] ) by vger . ker nel . or g Fr om : John Doe <j doe@
pl e. com > Recei ved: f r om sm t p. de. exam pl e. com ( [ 32. 1. 120. 11] ) by vger . ker nel . or g Fr om : Pam Pl i nas <ppl i nas@
pl e. com >
www.neutralbit.com
SMTP Information gathering
Recei ved: f r om m
pl e. m i l [ 192. 18. 1. 12] by gat ekeeper wi t h PO P3 ( f et chm ai l - 6. 3. 0 f et chm ai l - 6. 3. 0) f or <j doe@ exam pl e. com > ( si ngl e- dr op) ; M
( PST) ( PST) Recei ved: f r om m
pl e. m i l ( [ 192. 168. 1. 2] ) by m
pl e. m i l wi t h M i cr osof t SM TPSVC( 6. 0. 3790. 211) M i cr osof t SM TPSVC( 6. 0. 3790. 211) ; Tue, 3 Jan 2006 07: 44: 01 +0900 +0900
www.neutralbit.com
SMTP Information gathering
Recei ved: f r om l appy ( 192. 168. 1. 4) by pub. exam pl e. net ( qm ai l ) wi t h ESM TP I D M G 0007DA ( SSL/ TLS, 3DES, CBC m
+0200 Recei ved: f r om [ 24. 26. 7. 196] ( i l m . exam pl e. com [ 24. 26. 7. 196] ) ( usi ng TLSv1 wi t h ci pher DHE- RSA- AES256- SHA ( 256/ 256 bi t s) ) ( No cl i ent cer t i f i cat e r equest ed)
www.neutralbit.com
SMTP Information gathering
www.neutralbit.com
SMTP Information gathering
www.neutralbit.com
SMTP Information gathering
www.neutralbit.com
SMTP Information gathering
www.neutralbit.com
SMTP Information gathering
www.neutralbit.com
SMTP Information gathering
X- M ai l er : M i cr osof t O f f i ce O ut l ook, Bui l d 11. 0. 5510 User - Agent : Thunder bi r d 1. 5. 0. 7 ( W i ndows/ 20060909) X- M ai l er : Col dFusi on M X Appl i cat i on Ser ver X- M i m eO LE: Pr oduced By M i cr osof t M i m eO LE V6. 00. 2900. 2962 X- M ai l er : Evol ut i on 2. 2. 3 ( 2. 2. 3- 4. f c4) X- M ai l er : i Pl anet M essenger Expr ess 5. 2 Pat ch 2 ( bui l t Jul 14 2004) X- M ai l er : Lot us Not es Rel ease 5. 0. 6a Januar y 17, 2001 User - Agent : Squi r r el M ai l / 1. 4. 3a User - Agent : W ander l ust / 2. 12. 0 ( Your W i l dest Dr eam s) SEM I / 1. 14. 6 ( M ar uoka) FLI M / 1. 14. 7 APEL/ 10. 6 M ULE XEm acs/ 21. 5 ( bet a21) ( cor n) ( +CVS- 20050720) ( i 386- suse- l i nux)
www.neutralbit.com
SMTP Information gathering
www.neutralbit.com
SMTP Information gathering
www.neutralbit.com
SMTP Information gathering
www.neutralbit.com
SMTP Information gathering
Subj ect : Re: [ RELEASE 4] Test i ng pat ch #49192 Dat e: Tue, 21 Feb 2006 10: 21: 14 +0100 X- O r i gi nat i ng- I P: 10. 2. 1. 122 X- Vi r us- Scanned: by am avi sd- new- 20030616- p10 ( Debi an) X- Spam
Assassi n 3. 0. 2 ( 2004- 11- 1 X- Spam
www.neutralbit.com
SMTP Information gathering
M essage- I D: <Pi ne. LNX. 4. 21. 0611280421440. 26304- 100000@ exam pl e. or g> M essage- I D: <1103. 203. 41. 53. 196. 1128283359. squi r r el @ m ai l . exam pl e. com > M essage- I D: <11363603. 1154544476739. JavaM ai l . r oot @
pl e. net > Cont ent - Type: m ul t i par t / m i xed; boundar y=Appl e- M ai l - 1— 944594902
www.neutralbit.com
SMTP Information gathering
World Trade Center - Edificio Sur, 2ª Planta, Moll de Barcelona, Barcelona, E-08039 Spain T: +34 933 443 224 - F: +34 933 443 299 – info@neutralbit.com – http://www.neutralbit.com