
List of open ports :
Vulnerability found on port smtp (25/tcp)
Vulnerability found on port smtp (25/tcp)
Vulnerability found on port smtp (25/tcp)
Warning found on port smtp (25/tcp)
The remote SMTP server
answers to the EXPN and/or VRFY commands.
The EXPN command can be used to find
the delivery adress of mail aliases, or
even the full name of the recipients, and
the VRFY command may be used to check the
validity of an account.
Your mailer should not allow remote users to
use any of these commands, because it gives
them too much informations.
Solution : if you are using sendmail, add the
option
O PrivacyOptions=goaway
in /etc/sendmail.cf.
Risk factor : Low
CVE : CAN-1999-0531
Warning found on port smtp (25/tcp)
The remote STMP server seems to allow remote users to
send mail anonymously by providing a too long argument
to the HELO command (more than 1024 chars).
This problem may allow bad guys to send hate
mail, or threatening mail using your server
and keep their anonymity.
Risk factor : Low.
Solution : If you are using sendmail, upgrade to
version 8.9.x. If you do not run sendmail, contact
your vendor.
CVE : CAN-1999-0098
Warning found on port smtp (25/tcp)
The remote SMTP server allows the relaying. This means that
it allows spammers to use your mail server to send their mails to
the world, thus wasting your network bandwidth.
Risk factor : Low/Medium
Solution : configure your SMTP server so that it can't be used as a relay
any more.
CVE : CAN-1999-0512
Information found on port smtp (25/tcp)
Remote SMTP server banner :
H
@H
@ufpb.br IMS SMTP Receiver Version 0.83 Ready
500 Unknown or unimplemented command
Information found on port pop3 (110/tcp)
The remote POP server banner is :
+OK IMS POP3 Server 0.87 Ready <13377864.985877793.689@iza.mat.ufpb.br>
Vulnerability found on port netbios-ssn (139/tcp)
Warning found on port netbios-ssn (139/tcp)
Here is the browse list of the remote host :
IZA -
LAB1-02 -
LAB1-03 -
LAB1-07 -
This is potentially dangerous as this may help the attack
of a potential hacker by giving him extra targets to check for
Solution : filter incoming traffic to this port
Risk factor : Low
Warning found on port netbios-ssn (139/tcp)
The host SID can be obtained remotely. Its value is :
LABMAT : 5-21-1703050611-50012774-5979419
An attacker can use it to obtain the list of the local users of this host
Solution : filter the ports 137 to 139
Risk factor : Low
Warning found on port netbios-ssn (139/tcp)
The SID could be used to enumerate the names of the users
of this host.
(we only enumerated users name whose ID is between 1000 and 1200
for performance reasons)
This gives extra knowledge to a cracker, which
is not a good thing :
- Administrator account name : Administrador (id 500)
- Guest account name : Convidado (id 501)
- IZA$ (id 1000)
- Especiais (id 1001)
- Alunos (id 1002)
- super (id 1004)
- icsa (id 1006)
- angelus (id 1010)
- instalar (id 1011)
- sergio (id 1022)
- LABMAT01$ (id 1030)
- LABMAT02$ (id 1031)
- LABMAT03$ (id 1032)
- LABMAT04$ (id 1033)
- LABMAT05$ (id 1034)
- LABMAT06$ (id 1035)
- imsusers (id 1036)
- tl (id 1037)
- jlnv (id 1038)
- vetorial (id 1039)
- calculo (id 1040)
- pjso (id 1041)
- fpam (id 1043)
- atl (id 1045)
- fda (id 1046)
- mpgn (id 1047)
- rcc (id 1048)
- vlv (id 1049)
- ela (id 1050)
- jcsf (id 1051)
- jfls (id 1052)
- rrc (id 1053)
- rrm (id 1054)
- dkas (id 1055)
- jsrs (id 1056)
- jlo (id 1057)
- jcom (id 1058)
- isa (id 1059)
- lps (id 1060)
- ksmg (id 1061)
- cpf (id 1062)
- gdb (id 1063)
- mpl (id 1064)
- oba (id 1065)
- lfmb (id 1066)
- LABMAT_01$ (id 1067)
- LABMAT_04$ (id 1068)
- LABMAT_10$ (id 1069)
- LABMAT_02$ (id 1070)
- LABMAT_03$ (id 1071)
- LABMAT_05$ (id 1072)
- LABMAT_09$ (id 1073)
- LABMAT_07$ (id 1074)
- LABMAT_06$ (id 1075)
- LABMAT_12$ (id 1076)
- LABMAT_08$ (id 1077)
- LABMAT_11$ (id 1078)
- LABMAT_13$ (id 1079)
- alb (id 1080)
- AT (id 1082)
- ARBS (id 1083)
- jdm (id 1084)
- FC2 (id 1085)
- ECMS (id 1086)
- MAA (id 1087)
- JCS (id 1088)
- jdsm (id 1089)
- acms (id 1091)
- adrielle (id 1092)
- cmsl (id 1093)
- mjb (id 1094)
- vlad (id 1095)
- dea (id 1098)
- lenimar (id 1099)
- LEPACIN_04$ (id 1100)
- LEPACIN_01$ (id 1101)
- LEPACIN_02$ (id 1102)
- LEPACIN_03$ (id 1103)
- LEPACIN_05$ (id 1104)
- fclm (id 1105)
- LABMAT_14$ (id 1107)
- ERL (id 1108)
- sula (id 1109)
- amgs (id 1110)
- lloj (id 1111)
- nms (id 1112)
- cjs (id 1113)
- lri (id 1114)
- hacd (id 1115)
- acfc (id 1116)
- cgc (id 1117)
- glt (id 1118)
- jrvc (id 1119)
- lrf (id 1120)
- prlm (id 1121)
- wcm (id 1122)
- amf (id 1123)
- mms (id 1124)
- ecs (id 1125)
- lsl (id 1126)
- jls (id 1127)
- ft (id 1128)
- aj (id 1129)
- ass (id 1134)
- gcv (id 1135)
- LAB1-01$ (id 1136)
- LAB1-02$ (id 1137)
- LAB1-04$ (id 1138)
- LAB1-05$ (id 1139)
- LAB1-03$ (id 1140)
- LAB1-07$ (id 1141)
- LAB1-08$ (id 1142)
- LAB1-11$ (id 1143)
- LAB1-06$ (id 1144)
- LAB1-10$ (id 1145)
- LAB1-09$ (id 1146)
- LAB2-01$ (id 1147)
- LAB2-06$ (id 1148)
- LAB2-03$ (id 1149)
- cac (id 1150)
- jacq (id 1151)
- LAB2-05$ (id 1152)
- LAB2-04$ (id 1153)
- LAB2-02$ (id 1154)
- amrn (id 1155)
- ccb (id 1156)
- jiln (id 1157)
- amo (id 1171)
- cor (id 1172)
- aem (id 1173)
- arslp (id 1174)
- epa (id 1175)
- apsm (id 1176)
- epg (id 1177)
- inc (id 1178)
- mcab (id 1179)
- lif (id 1180)
- fnl (id 1181)
- jrs (id 1182)
- spg (id 1183)
- jwl (id 1184)
- ffsn (id 1185)
- mrnd (id 1186)
- woa (id 1187)
- mds (id 1188)
- spgo (id 1189)
- asn (id 1190)
- jjb (id 1191)
Risk factor : Medium
Solution : filter incoming connections to port 139
Information found on port general/tcp
Nmap found that this host is running Windows NT4 / Win95 / Win98
Warning found on port netbios-ns (137/udp)
. The following 9 NetBIOS names have been gathered :
IZA
IZA
LABMAT
LABMAT
LABMAT
LABMAT
IZA
LABMAT
__MSBROWSE__
. The remote host has the following MAC address on its adapter :
0x00 0x00 0xb4 0x45 0x7f 0xa6
If you do not want to allow everyone to find the NetBios name
of your computer, you should filter incoming traffic to this port.
Risk factor : Medium
Information found on port general/udp
For your information, here is the traceroute to 150.165.135.194 :
150.165.250.100
150.165.254.254
150.165.254.35
150.165.253.133
150.165.135.194
Warning found on port general/icmp
The remote host answered to an ICMP_MASKREQ
query and sent us its netmask.
An attacker can use this information to
understand how your network is set up
and how the routing is done. This may
help him to bypass your filters.
Solution : reconfigure the remote host so
that it does not answer to those requests.
Set up filters that deny ICMP packets of
type 17.
Risk factor : Low
CVE : CAN-1999-0524