tcpdump for sniffing POP3 -- methods ?

From: John Fox (readbsd_at_mind.net)
Date: 04/13/04

  • Next message: Putinas Piliponis: "Re: tcpdump for sniffing POP3 -- methods ?"
    Date: Tue, 13 Apr 2004 11:03:23 -0700
    To: freebsd-isp@freebsd.org
    
    

    We've got a Windows machine running IMail and authenticating
    POP3 from an NT Primary Domain Controller.

    Our plan is to move these users over to our UNIX system, but we
    don't have a record of their passwords. This means we need to
    either

    1) Grab them out of the files on the PDC. (I think this is
    not possible.)

    2) Obtain them by sniffing the POP3 traffic being sent
    to the Imail server.

    I think #2 is the only possibility, and I haven't made much
    use of tcpdump, so while I do know how to run it and
    specify a host to listen to, I've no idea how to isolate
    the clear-text stuff (containing the usernames and passwords)
    from all the other traffic.

    Any suggestions would be greatly appreciated.

    With thanks and regards,

    -John

    --
    +---------------------------------------------------------------------------+
    | John Fox <jjf @ mind.net>    |   System Administrator   | InfoStructure   |
    +---------------------------------------------------------------------------+
    | I used to trust the media to tell me the truth, tell us the truth         |
    | But now I've seen the payoffs everywhere I look                           |
    | Who can you trust when everyone's a crook?                                |
    |             -- Queensryche, "Revolution Calling"                          |
    +---------------------------------------------------------------------------+
    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"
    

  • Next message: Putinas Piliponis: "Re: tcpdump for sniffing POP3 -- methods ?"

    Relevant Pages

    • Re: Wardriving
      ... I'm assuming that POP3 doesn't send passwords in clear ... take a genius to search for USER and PASS in a packet trace. ... That seems odd. ...
      (uk.rec.motorcycles)
    • RE: POP3 Access
      ... Keep in mind that POP3 by default sends passwords in clear text, ... Help Secure Post Office Protocol Client Access in Exchange ... Microsoft Small Business Server Support ...
      (microsoft.public.windows.server.sbs)
    • Re[2]: SV: [SLE] Problems With dial-up mail
      ... >> email programs to use regular POP3, then they will not be prompted for a ... C> passwords for unencrypted sessions. ... good point Carlos, however, his apparent problem is POP3s, and he does not ... suggested just trying the standard POP3 protocol. ...
      (SuSE)
    • RE: POP3 Access
      ... >Keep in mind that POP3 by default sends passwords in ... >POP3 traffic between client and server: ... Help Secure Post Office Protocol Client ... >Microsoft Small Business Server Support ...
      (microsoft.public.windows.server.sbs)
    • RE: LM and NTLM Hashes
      ... Telnet, Pop3, and FTP all send clear-text passwords by default. ... I saw that pop3 clients send passwords in text mode. ... protect passwords from email clients? ...
      (Security-Basics)