7
SMTP HELP detection
SMTP
2003/11/13
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
2.0
Corrected the plugin structure and added the accuracy values in 1.3. Improved the pattern matching and added the changelog in 2.0
tcp
25
open|send HELP\n|sleep|close|pattern_exists 220 *HELP*
70
This plugin was written with the ATK Attack Editor.
Most mail transfer agents
Hardened mail transfer agents
Configuration
The mail server allows the HELP commando. A malicous user could use this to verify the availablity of certain SMTP commands. He could also enumerate the mail server.
Do not allow the HELP command to prevent further enumeration. Check the manual of your mail server howto set the configuration correctly. Additionally prevent unwanted SMTP connections with firewalling.
10 minutes
Yes
Yes
Yes
Low
9
9
2
6
Nessus is able to do the check automated. Mostly attackers prefer to test the HELP support with a simple telnet or NetCat connection.
Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X
http://www.computec.ch