Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

pop3 smtp

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
13 posts • Page 1 of 1
Author
Message
Bornio
Tux's lil' helper
Tux's lil' helper
User avatar
Posts: 129
Joined: Mon Dec 16, 2002 5:25 pm

pop3 smtp

  • Quote

Post by Bornio » Sun Mar 11, 2007 7:19 pm

I intercepted this from a trojan that infected me, and I am not exactly sure what this means.

Code: Select all

250 2.1.0 Flushed 35si6742153wra
250 2.0.0 OK 1173624242 35si6742153wra
Does anybody know what "Flushed" means, and what is the value after it?
Same for the 2 values after "OK" ?

Thank you.
Top
elgato319
Guru
Guru
Posts: 546
Joined: Thu Sep 15, 2005 9:45 am

  • Quote

Post by elgato319 » Tue Mar 13, 2007 11:03 am

Sounds like SMTP or SMTP Auth.

Got some more logs?
Top
Bornio
Tux's lil' helper
Tux's lil' helper
User avatar
Posts: 129
Joined: Mon Dec 16, 2002 5:25 pm

  • Quote

Post by Bornio » Tue Mar 13, 2007 11:11 am

i am curios if its the username and password there, and they are hashed.
and if they are, who hashes them? is it done local or server side, etc.
Top
elgato319
Guru
Guru
Posts: 546
Joined: Thu Sep 15, 2005 9:45 am

  • Quote

Post by elgato319 » Tue Mar 13, 2007 12:23 pm

They could be hashed (base64/md5/sha-1)
or even plain text.

hard to tell

edit: those are not base64 encoded
Top
Bornio
Tux's lil' helper
Tux's lil' helper
User avatar
Posts: 129
Joined: Mon Dec 16, 2002 5:25 pm

  • Quote

Post by Bornio » Tue Mar 13, 2007 12:30 pm

the question is, hashed/encoded Where?
When I auth to the server, at some point, I have to enter the username/password in cleartext.
It just does not sound logical that an already (Pre)Hashed password is being sent for checking.
Top
timeBandit
Bodhisattva
Bodhisattva
User avatar
Posts: 2719
Joined: Fri Dec 31, 2004 1:54 am
Location: here, there or in transit

Re: pop3 smtp

  • Quote

Post by timeBandit » Tue Mar 13, 2007 12:31 pm

Bornio wrote:I intercepted this from a trojan that infected me, and I am not exactly sure what this means.

Code: Select all

250 2.0.0 OK 1173624242 35si6742153wra
Does anybody know what ... the 2 values after "OK" [mean]?
The first value is a UNIX timestamp: 1173624242 -> Sun, 11 Mar 2007 14:44:02 GMT. Can't help you with the second, but your SMTP server's documentation will probably explain the details logged for the 200, 210 and/or 250 error codes.
Plants are pithy, brooks tend to babble--I'm content to lie between them.
Super-short f.g.o checklist: Search first, strip comments, mark solved, help others.
Top
Bornio
Tux's lil' helper
Tux's lil' helper
User avatar
Posts: 129
Joined: Mon Dec 16, 2002 5:25 pm

  • Quote

Post by Bornio » Tue Mar 13, 2007 12:47 pm

I dont have the documentation for Google SMTP client :wink:
Top
Bornio
Tux's lil' helper
Tux's lil' helper
User avatar
Posts: 129
Joined: Mon Dec 16, 2002 5:25 pm

  • Quote

Post by Bornio » Tue Mar 13, 2007 3:07 pm

Let me try the question another way:
Does anybody knows if its possible to auth to google mail with prehashed password. I already send the username, now its up to the server to compare my server stored hash pass to my local, just-sent hash pass.

Any ideas?
Top
elgato319
Guru
Guru
Posts: 546
Joined: Thu Sep 15, 2005 9:45 am

  • Quote

Post by elgato319 » Tue Mar 13, 2007 3:11 pm

Code: Select all

220 smtp.google.com ESMTP
ehlo bla.com
250-smtp.google.com Hello
250-ENHANCEDSTATUSCODES
250-PIPELINING
250-8BITMIME
250-SIZE 20000000
250-STARTTLS
250-DELIVERBY
250 HELP
looks like google's smtp needs to be authenticated via TLS first.
after this you may send a cleartext password, because the line is encrypted
Top
timeBandit
Bodhisattva
Bodhisattva
User avatar
Posts: 2719
Joined: Fri Dec 31, 2004 1:54 am
Location: here, there or in transit

  • Quote

Post by timeBandit » Tue Mar 13, 2007 3:52 pm

Bornio wrote:I dont have the documentation for Google SMTP client :wink:
You didn't previously name the specific source. :wink:
Plants are pithy, brooks tend to babble--I'm content to lie between them.
Super-short f.g.o checklist: Search first, strip comments, mark solved, help others.
Top
Bornio
Tux's lil' helper
Tux's lil' helper
User avatar
Posts: 129
Joined: Mon Dec 16, 2002 5:25 pm

  • Quote

Post by Bornio » Tue Mar 13, 2007 5:02 pm

you are right sorry.
That sniffed traffic is from a trojan, which once I got infected it sends some stuff to some gmail account. the sniffer showed that, while i was (clearly) hoping to get the clear text password. I am curios how the authentication is done and how I can find out the true password....
Top
timeBandit
Bodhisattva
Bodhisattva
User avatar
Posts: 2719
Joined: Fri Dec 31, 2004 1:54 am
Location: here, there or in transit

  • Quote

Post by timeBandit » Tue Mar 13, 2007 5:22 pm

Bornio wrote:That sniffed traffic is from a trojan, which once I got infected it sends some stuff to some gmail account. the sniffer showed that, while i was (clearly) hoping to get the clear text password.
:idea: Based on elgato319's comment that Gmail authentication appears to be in clear text: if you have the Gmail address the bot contacts, did you try to log in using the supposed hash as the actual password? Maybe it only looks like a hash...?
Plants are pithy, brooks tend to babble--I'm content to lie between them.
Super-short f.g.o checklist: Search first, strip comments, mark solved, help others.
Top
Bornio
Tux's lil' helper
Tux's lil' helper
User avatar
Posts: 129
Joined: Mon Dec 16, 2002 5:25 pm

  • Quote

Post by Bornio » Tue Mar 13, 2007 5:48 pm

thought about it. its not. :(
Top
Post Reply

13 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic