Hacettepe.edu.tr Mail Server Vulnerability
One of the four biggest servers of Hacettepe.edu.tr, chromosome.hacettepe.edu.tr’s mail server has a vulnerabilitiy that you may send an e-mail from any address to any @hacettepe.edu.tr without any authentication.
Server IP Address:
Server Address: chromosome.hacettepe.edu.tr
Port: 25
Vulnerability: Sending e-mail without authorization
Current Status: Port Closed
Read more to check 2010 March NMap records ;)
NMap Intense Scan Record at 2010 March;
Starting Nmap 5.21 ( http://nmap.org ) at 2010-03-03 19:09 GTB Standart Saati
NSE: Loaded 36 scripts for scanning.
Initiating Parallel DNS resolution of 1 host. at 19:09
Completed Parallel DNS resolution of 1 host. at 19:09, 0.27s elapsed
Initiating SYN Stealth Scan at 19:09
Scanning chromosome.hacettepe.edu.tr (194.27.160.6) [1000 ports]
Discovered open port 80/tcp on 194.27.160.6
Discovered open port 22/tcp on 194.27.160.6
Discovered open port 53/tcp on 194.27.160.6
Discovered open port 111/tcp on 194.27.160.6
Discovered open port 5190/tcp on 194.27.160.6
Discovered open port 32770/tcp on 194.27.160.6
Discovered open port 1863/tcp on 194.27.160.6
Increasing send delay for 194.27.160.6 from 0 to 5 due to max_successful_tryno increase to 5
Increasing send delay for 194.27.160.6 from 5 to 10 due to max_successful_tryno increase to 6
Warning: 194.27.160.6 giving up on port because retransmission cap hit (6).
Completed SYN Stealth Scan at 19:11, 89.92s elapsed (1000 total ports)
Initiating Service scan at 19:11
Scanning 7 services on chromosome.hacettepe.edu.tr (194.27.160.6)
Completed Service scan at 19:11, 7.56s elapsed (7 services on 1 host)
Initiating RPCGrind Scan against chromosome.hacettepe.edu. at 19:11
Completed RPCGrind Scan against chromosome.hacettepe.edu. at 19:11, 4.47s elapsed (2 ports)
Initiating OS detection (try #1) against chromosome.hacettepe.edu.tr (194.27.160.6)
Retrying OS detection (try #2) against chromosome.hacettepe.edu.tr (194.27.160.6)
Initiating Traceroute at 19:11
Completed Traceroute at 19:11, 3.23s elapsed
Initiating Parallel DNS resolution of 19 hosts. at 19:11
Completed Parallel DNS resolution of 19 hosts. at 19:11, 5.56s elapsed
NSE: Script scanning 194.27.160.6.
NSE: Starting runlevel 1 (of 1) scan.
Initiating NSE at 19:11
Completed NSE at 19:12, 50.97s elapsed
NSE: Script Scanning completed.
Nmap scan report for chromosome.hacettepe.edu.tr (194.27.160.6)
Host is up (0.15s latency).
rDNS record for 194.27.160.6: ns04.hacettepe.edu.tr
Not shown: 973 closed ports
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 3.9p1 (protocol 1.99)
| ssh-hostkey: 1024 a8:3b:28:f6:1b:ff:96:83:a6:0b:dc:f3:8f:3d:f9:4f (DSA)
|_1024 e6:68:fc:27:11:47:1b:72:ca:ce:78:13:4b:65:10:47 (RSA)
25/tcp filtered smtp
53/tcp open domain ISC BIND 9.2.5
80/tcp open http Apache httpd 2.0.54 ((Unix))
111/tcp open rpcbind 2 (rpc #100000)
135/tcp filtered msrpc
161/tcp filtered snmp
445/tcp filtered microsoft-ds
1026/tcp filtered LSA-or-nterm
1027/tcp filtered IIS
1028/tcp filtered unknown
1029/tcp filtered ms-lsa
1434/tcp filtered ms-sql-m
1720/tcp filtered H.323/Q.931
1863/tcp open tcpwrapped
2701/tcp filtered sms-rcinfo
2702/tcp filtered sms-xfer
2710/tcp filtered unknown
2967/tcp filtered symantec-av
4111/tcp filtered unknown
4242/tcp filtered unknown
4444/tcp filtered krb524
4662/tcp filtered edonkey
5190/tcp open tcpwrapped
6346/tcp filtered gnutella
6881/tcp filtered bittorrent-tracker
32770/tcp open status 1 (rpc #100024)
Device type: general purpose|printer|PBX|firewall|WAP|remote management
Running (JUST GUESSING) : Linux 2.6.X|2.4.X (93%), HP embedded (91%), Lexmark embedded (89%), Toshiba Linux 2.4.X (88%), Aruba ArubaOS 3.X (87%), Gemtek embedded (87%), Siemens embedded (87%)
Aggressive OS guesses: Linux 2.6.9 – 2.6.28 (93%), Linux 2.6.22 (92%), Linux 2.6.9 (Red Hat Enterprise Linux, x86_64) (92%), HP Designjet Z3100ps printer (91%), Linux 2.6.9 (91%), Linux 2.6.9 – 2.6.30 (90%), Linux 2.6.13 – 2.6.28 (90%), Linux 2.6.15-27 (Ubuntu) (90%), Linux 2.6.9 – 2.6.24 (90%), Linux 2.6.9-55.0.2.EL (Red Hat Enterprise Linux) (90%)
No exact OS matches for host (test conditions non-ideal).
Uptime guess: 20.390 days (since Thu Feb 11 09:50:45 2010)
Network Distance: 20 hops
TCP Sequence Prediction: Difficulty=204 (Good luck!)
IP ID Sequence Generation: All zeros
TRACEROUTE (using port 113/tcp)
HOP RTT ADDRESS
1 0.00 ms 192.168.1.1
2 0.00 ms 78.170.48.1
3 16.00 ms 81.212.77.33
4 …
5 16.00 ms 81.212.215.17
6 16.00 ms 81.212.209.74
7 15.00 ms 212.156.119.246
8 78.00 ms 212.156.103.13
9 140.00 ms ldn-b3-link.telia.net (213.248.103.153)
10 172.00 ms ldn-bb1-link.telia.net (80.91.251.166)
11 188.00 ms hbg-bb2-link.telia.net (80.91.254.6)
12 204.00 ms bpt-b4-link.telia.net (80.91.247.61)
13 204.00 ms invitel-ic-134649-bpt-b4.c.telia.net (213.248.93.166)
14 204.00 ms xe-0-2-0.bix-p2.invitel.net (213.163.54.158)
15 219.00 ms xe-0-3-0.ist-c1.tr.invitel.net (213.163.54.102)
16 141.00 ms 213.197.64.38
17 157.00 ms asy86.asy52.tellcom.com.tr (85.29.52.86)
18 157.00 ms 193.140.0.30
19 141.00 ms 172.15.0.2
20 141.00 ms ns04.hacettepe.edu.tr (194.27.160.6)
Nmap done: 1 IP address (1 host up) scanned in 171.72 seconds
Raw packets sent: 1399 (63.184KB) | Rcvd: 1082 (45.486KB)
