113-pentesting-ident.md (5067B)
1 --- 2 title: "113 - Pentesting Ident" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/113-pentesting-ident.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/113-pentesting-ident.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 113 - Pentesting Ident 14 15 ## Basic Information 16 17 The **Identification Protocol (Ident)** lets one host ask the other end of an existing TCP connection which local operating-system identity owns that connection. A query contains the server-side and client-side port pair, and the Ident server normally listens on TCP/113.<sup>[[2]](#references)</sup> 18 19 RFC 1413 explicitly warns that an Ident response is not authentication or authorization: it is unauthenticated information asserted by the queried host and may be forged or intentionally misleading. It can still disclose usernames and service-account relationships during enumeration.<sup>[[2]](#references)</sup> 20 21 **Default port:** 113 22 23 ```text 24 PORT STATE SERVICE 25 113/tcp open ident 26 ``` 27 28 ## **Enumeration** 29 30 ### **Manual - Get user/Identify the service** 31 32 If a machine runs Ident and you have a TCP connection from local source port 43218 to its Samba port 445, query the pair `445, 43218`. A response may identify the remote account owning that connection; do not treat it as trusted proof of identity.<sup>[[2]](#references)</sup> 33 34  35 36 If you just press Enter when you connect to the service: 37 38  39 40 Other errors: 41 42  43 44 ### Nmap 45 46 Nmap's `auth-owners` script queries Ident for the owner of each suitable open TCP connection. Results depend on the target's Ident policy and are not available for every service or network path.<sup>[[3]](#references)</sup> 47 48 ```text 49 PORT STATE SERVICE VERSION 50 22/tcp open ssh OpenSSH 4.3p2 Debian 9 (protocol 2.0) 51 |_auth-owners: root 52 | ssh-hostkey: 53 | 1024 88:23:98:0d:9d:8a:20:59:35:b8:14:12:14:d5:d0:44 (DSA) 54 |_ 2048 6b:5d:04:71:76:78:56:96:56:92:a8:02:30:73:ee:fa (RSA) 55 113/tcp open ident 56 |_auth-owners: identd 57 139/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: LOCAL) 58 |_auth-owners: root 59 445/tcp open netbios-ssn Samba smbd 3.0.24 (workgroup: LOCAL) 60 |_auth-owners: root 61 ``` 62 63 ### Ident-user-enum 64 65 [**Ident-user-enum**](https://github.com/pentestmonkey/ident-user-enum) is a simple PERL script to query the ident service (113/TCP) in order to determine the owner of the process listening on each TCP port of a target system. The list of usernames gathered can be used for password guessing attacks on other network services. It can be installed with `apt install ident-user-enum`.<sup>[[1]](#references)</sup> 66 67 ```text 68 root@kali:/opt/local/recon/192.168.1.100# ident-user-enum 192.168.1.100 22 113 139 445 69 ident-user-enum v1.0 ( http://pentestmonkey.net/tools/ident-user-enum ) 70 71 192.168.1.100:22 root 72 192.168.1.100:113 identd 73 192.168.1.100:139 root 74 192.168.1.100:445 root 75 ``` 76 77 ### Shodan 78 79 - `oident` 80 81 ## Files 82 83 identd.conf 84 85 ## HackTricks Automatic Commands 86 87 ```text 88 Protocol_Name: Ident #Protocol Abbreviation if there is one. 89 Port_Number: 113 #Comma separated if there is more than one. 90 Protocol_Description: Identification Protocol #Protocol Abbreviation Spelled out 91 92 Entry_1: 93 Name: Notes 94 Description: Notes for Ident 95 Note: | 96 The Ident Protocol is used over the Internet to associate a TCP connection with a specific user. Originally designed to aid in network management and security, it operates by allowing a server to query a client on port 113 to request information about the user of a particular TCP connection. 97 98 https://book.hacktricks.wiki/en/network-services-pentesting/113-pentesting-ident.html 99 100 Entry_2: 101 Name: Enum Users 102 Description: Enumerate Users 103 Note: apt install ident-user-enum ident-user-enum {IP} 22 23 139 445 (try all open ports) 104 ``` 105 106 ## References 107 108 - [1] [ident-user-enum - pentestmonkey](https://github.com/pentestmonkey/ident-user-enum) 109 - [2] [RFC 1413 — Identification Protocol](https://www.rfc-editor.org/rfc/rfc1413.html) 110 - [3] [Nmap NSE documentation — `auth-owners`](https://nmap.org/nsedoc/scripts/auth-owners.html)