May 2017
Intermediate to advanced
416 pages
21h 33m
English
The behavior described previously can be observed in other protocols that support NTLM authentication, such as HTTP, IMAP, SMTP, TELNET, NNTP, and POP3. If any of these protocols have NTLM authentication enabled, they will disclose the NetBIOS, DNS, and OS build version information if an authentication request with null credentials is sent. And there are NSE scripts available that we can implement to quickly use this technique to obtain additional network information, such as http-ntlm-info, smtp-ntlm-info, telnet-ntlm-info, nntp-ntlm-info, and pop3-ntlm-info.
Read now
Unlock full access