Forums: Banner Removal - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Banner Removal

#1 User is offline   vnet576 

  • Specialist
  • Icon
  • Group: Members
  • Posts: 1,000
  • Joined: 01-August 03

Posted 23 January 2004 - 01:03 PM

Most hackers when searching for a target to exploit will do a banner scan to find the type of service they're looking for, IIS Web Server, for example. Removing the banner is an excelent deterent against all but the most persistant hackers who are determined to get into a specific target. These tools remove the banner from MS and Apache servers.

http://www.nstalker....ense/banner.php
0

#2 User is offline   Kynroxes 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 263
  • Joined: 20-October 03

Posted 24 January 2004 - 03:04 AM

w00t !! so sweet these tools, tks vnet576 very much. ;)
0

#3 User is offline   hks3207 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 58
  • Joined: 21-October 05

Posted 27 October 2005 - 11:36 AM

Very usefull man, thanks for sharing ;)
0

#4 User is offline   GhostShell 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 343
  • Joined: 07-May 05

Posted 27 October 2005 - 03:40 PM

Couldnt you just hex the banner out of most apps? But very nice thanks man!
"As a young boy, I was taught in high school that hacking was cool." -Kevin Mitnick

"It's easy to point and click programs, but thats not real hacking." -illwill
0

#5 User is offline   dw-chow 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 127
  • Joined: 25-March 04

Posted 08 November 2005 - 09:23 AM

too bad it doesn't list exchange server removal. :(
0

#6 User is offline   stay 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 493
  • Joined: 19-June 05

Posted 08 November 2005 - 09:30 AM

View Postdw-chow, on Nov 8 2005, 07:23 PM, said:

too bad it doesn't list exchange server removal. :(


http://www.microsoft...r/secmod43.mspx

Quote

Changing the SMTP Banner

The less information you provide an attacker, the more difficult it is to attack your system. One way an attacker may attempt to gain information about which version of Exchange is being run is to use Telnet to connect to the SMTP service. By default, when you connect to the SMTP service on an Exchange server, the following banner is displayed:

220 hostname . domain .com Microsoft ESMTP MAIL Service, Version: 5.0.2195.1600 ready at current date and time.

You should consider changing this on all back-end Exchange servers so that it does not display the specific version. You may also wish to include a legal statement that unauthorized use of the SMTP service is prohibited.

To modify the Windows 2000 SMTP banner

1. Using a metabase editing tool such as MetaEdit, locate:

Lm\Smtpsvc\ virtual server number.

2. Click Edit , click New , and then click String.

3. Verify that the entry in the ID box is Other, and then type 36907 (decimal) on the right side of the ID box.

4. In the Data box, type the banner that you want to be displayed.

5. Stop, and then restart the SMTP virtual server or the SMTP service.

To confirm that the banner has been changed, Telnet to port 25 of the virtual server (the default setting). The "ESMTP MAIL Service, Version: 5.0.2195.1600" banner should no longer be displayed. However the fully qualified domain dame (as it was entered in the SMTP service properties) and the date and time are still displayed.

0

#7 User is offline   MpR 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 41
  • Joined: 26-October 04

Posted 10 November 2005 - 12:21 AM

When removing a banner through Hex it can be a Pain in the arse at times depending on the software, alot of times Ive found with FTPD applications the banner cant be "removed" as the application crashes when theres a request for it .. but it can be changed easily for the most part :)
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting