About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2002-12-04, 06:12
SoCal SoCal is offline
Regular
 
Default accessing e-mail/user accounts on a remote server....

how would i go about doing this? i don't know shit about accessing another system. i need to gather some info from this server... mainly, im looking for one email that was sent out from a user.... i'll spare the story since no one probably gives a shit anyway =) will any of this help? and where do i go from here?

6 open ports i know of....
Port 113 (ident)

Port 110 (pop3)
message returned - "+OK Teapop [v0.3.3]"

Port 80 (http-www)
Apache/1.3.22 Server

Port 25 (smtp)
mesage returned-
This is sendmail version 8.11.6
Topics:
HELO EHLO MAIL RCPT DATA
RSET NOOP QUIT HELP VRFY
EXPN VERB ETRN DSN AUTH
STARTTLS
For more info use "HELP <topic>"

Port 22 (ssh)
SSH-1.99-OpenSSH_3.1p1

Port 21 (ftp)
FTP server (Version wu-2.6.1-20

[a telnet connect to port 21 gets....]
Connection established
220 host25 Microsoft FTP Service (Version 4.0).
help214-The following commands are recognized(* ==>'s unimplemented).

ABOR
ACCT
ALLO
APPE
CDUP
CWD
DELE
HELP
LIST
MKD
MODE
NLST
NOOP
PASS
PASV
PORT
PWD
QUIT
REIN
REST
RETR
RMD
RNFR
RNTO
SITE
SIZE
SMNT
STAT
STOR
STOU
STRU
SYST
TYPE
USER
XCUP
XCWD
XMKD
XPWD
XRMD

additionally.......
cuteftp with user/anonymous pass/anonymous grants access to the ftp dir



[This message has been edited by SoCal (edited 12-04-2002).]
 #2 
Old 2002-12-04, 12:38
cense cense is offline
Regular
 
Default Re: accessing e-mail/user accounts on a remote server....

I see three highly vulnerable services by which one can gain unauthorized access to this machine... check on a exploit site for more info (security focus, etc).

Since both POP and SMTP are open, with the users password, you can obtain their mail. Chances are the SMTP server will allow you to forge mail as if sent from that person, a clever scheme of social engineering mixed with forged email be useful.

Basically you need to either break into the system and access their mail folder directly or download the message through the POP server with user/pass authentication.
 #3 
Old 2002-12-04, 23:47
SoCal SoCal is offline
Regular
 
Default Re: accessing e-mail/user accounts on a remote server....

thanx for pointing me to security focus.... after doing a little searching around here and there, one short tutorial i came across was for netcat/cryptcat and how as far as smtp goes, you could log on and send forged outgoing mail as you mentioned.. which can be useful too....

i'm still reading articles.. and i found a top 50 list of tools at insecure....
 #4 
Old 2002-12-05, 00:11
cense cense is offline
Regular
 
Default Re: accessing e-mail/user accounts on a remote server....

Good start.

Heres a hint about the forged mail aspect: telnet to the smtp port on this server.
 #5 
Old 2002-12-05, 01:40
SoCal SoCal is offline
Regular
 
Default Re: accessing e-mail/user accounts on a remote server....

you know, i thought i could do that.. i screwed some setting and it didnt work yesterday.. got it this time... pop3 is a little different story.. trying to get it to "help" me.. no go so far, just guesswork on the commands so far

my telnet conversation with TeaPop the pop3 server.....

connecting to ***.***.**.***
Connection established
+OK Teapop [v0.3.3] - Teaspoon stirs around again <1039058523.70618C47@******>

help -ERR help? I'm not quite sure what you mean, Master.

user -ERR I won't serve a Master who doesn't know their own name.

user ****** +OK Welcome, do you have any type of ID?
 #6 
Old 2002-12-05, 01:44
SoCal SoCal is offline
Regular
 
Default Re: accessing e-mail/user accounts on a remote server....

ahh.. found... now if i knew where to look for the password file....

[This message has been edited by SoCal (edited 12-05-2002).]
 #7 
Old 2002-12-05, 02:22
SoCal SoCal is offline
Regular
 
Default Re: accessing e-mail/user accounts on a remote server....

they use e-mail with a virtual domain within their normal domain h**p://name.com
user@name-somethingelse.com

teapop documentation says
------
The domains that teapop serves are defined using the teapop.passwd
file, which lives in the /etc/teapop directory.

The file itself has several good examples in it, but for our example
we will assume that you want to use apache-style .htpasswd files
for authentication. This can be handy because there are various
user-management utilities to work with these files floating around
the net (they can also be a good idea even for your "real" domains
so that you aren't forced to use the same password for pop3 and for
login -- why using the same password for both can be a bad idea is
beyond the scope of this document).

So, what to do... first of all you need to create a .htpasswd file
for the virtual domain. I usually put these in the same subdirectory
as the mailboxes (in the example, I would use the file
/var/virtmail/myfriendsdomain.org/.htpasswd). Once you have created
the file (using the htpasswd program, perhaps), add a line like
this to the teapop.passwd file (near the end of the file, in-between
the "emtpy:*:....." and the "default:*:reject" lines):

myfriendsdomain.org:*:htpasswd:/var/virtmail/
myfriendsdomain.org:0:teapop:teapop:/var/virt
mail/myfriendsdomain.org/.htpasswd:9999:

The two "teapop"s tell teapop to run as user "teapop" and group
"teapop". It'd probably be better to tell it to run as group "mail",
but instead, I just added the user "teapop" to the "mail" group
(hey, my system just kind of evolved...). If you want to do this,
use the command:

gpasswd -a teapop mail

[This message has been edited by SoCal (edited 12-05-2002).]

[This message has been edited by SoCal (edited 12-05-2002).]
 #8 
Old 2002-12-06, 05:09
cense cense is offline
Regular
 
Default Re: accessing e-mail/user accounts on a remote server....

Excellent research. Nice to see someone trying to solve their own problems... maybe a few too many unnecessary updates but still.

Anyways. You're on the right track, definately. If I had seen this earlier I would have told you that POP3 servers dont expect telnet sessions and thus do not have any help listings, etc. You must know the commands and what they do. However, you seemed to have figured this out.

Anyways, looking at the documentation is always a good way to go if you need to understand how something works in order to use it or for whatever other purpose you may have in mind for it.
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics