daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

113-pentesting-ident.md (5067B)


      1 ---
      2 title: "113 - Pentesting Ident"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/113-pentesting-ident.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/113-pentesting-ident.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 113 - Pentesting Ident
     14 
     15 ## Basic Information
     16 
     17 The **Identification Protocol (Ident)** lets one host ask the other end of an existing TCP connection which local operating-system identity owns that connection. A query contains the server-side and client-side port pair, and the Ident server normally listens on TCP/113.<sup>[[2]](#references)</sup>
     18 
     19 RFC 1413 explicitly warns that an Ident response is not authentication or authorization: it is unauthenticated information asserted by the queried host and may be forged or intentionally misleading. It can still disclose usernames and service-account relationships during enumeration.<sup>[[2]](#references)</sup>
     20 
     21 **Default port:** 113
     22 
     23 ```text
     24 PORT    STATE SERVICE
     25 113/tcp open  ident
     26 ```
     27 
     28 ## **Enumeration**
     29 
     30 ### **Manual - Get user/Identify the service**
     31 
     32 If a machine runs Ident and you have a TCP connection from local source port 43218 to its Samba port 445, query the pair `445, 43218`. A response may identify the remote account owning that connection; do not treat it as trusted proof of identity.<sup>[[2]](#references)</sup>
     33 
     34 ![Enumeration - Manual - Get user/Identify the service: If a machine is running the service ident and samba (445) and you are connected to samba using the port 43218. You can get which...](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28843%29.png)
     35 
     36 If you just press Enter when you connect to the service:
     37 
     38 ![Enumeration - Manual - Get user/Identify the service: If you just press Enter when you connect to the service](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28159%29.png)
     39 
     40 Other errors:
     41 
     42 ![Enumeration - Manual - Get user/Identify the service: If you just press Enter when you connect to the service](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28359%29.png)
     43 
     44 ### Nmap
     45 
     46 Nmap's `auth-owners` script queries Ident for the owner of each suitable open TCP connection. Results depend on the target's Ident policy and are not available for every service or network path.<sup>[[3]](#references)</sup>
     47 
     48 ```text
     49 PORT    STATE SERVICE     VERSION
     50 22/tcp  open  ssh         OpenSSH 4.3p2 Debian 9 (protocol 2.0)
     51 |_auth-owners: root
     52 | ssh-hostkey:
     53 |   1024 88:23:98:0d:9d:8a:20:59:35:b8:14:12:14:d5:d0:44 (DSA)
     54 |_  2048 6b:5d:04:71:76:78:56:96:56:92:a8:02:30:73:ee:fa (RSA)
     55 113/tcp open  ident
     56 |_auth-owners: identd
     57 139/tcp open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: LOCAL)
     58 |_auth-owners: root
     59 445/tcp open  netbios-ssn Samba smbd 3.0.24 (workgroup: LOCAL)
     60 |_auth-owners: root
     61 ```
     62 
     63 ### Ident-user-enum
     64 
     65 [**Ident-user-enum**](https://github.com/pentestmonkey/ident-user-enum) is a simple PERL script to query the ident service (113/TCP) in order to determine the owner of the process listening on each TCP port of a target system. The list of usernames gathered can be used for password guessing attacks on other network services. It can be installed with `apt install ident-user-enum`.<sup>[[1]](#references)</sup>
     66 
     67 ```text
     68 root@kali:/opt/local/recon/192.168.1.100# ident-user-enum 192.168.1.100 22 113 139 445
     69 ident-user-enum v1.0 ( http://pentestmonkey.net/tools/ident-user-enum )
     70 
     71 192.168.1.100:22  root
     72 192.168.1.100:113 identd
     73 192.168.1.100:139 root
     74 192.168.1.100:445 root
     75 ```
     76 
     77 ### Shodan
     78 
     79 - `oident`
     80 
     81 ## Files
     82 
     83 identd.conf
     84 
     85 ## HackTricks Automatic Commands
     86 
     87 ```text
     88 Protocol_Name: Ident    #Protocol Abbreviation if there is one.
     89 Port_Number:  113     #Comma separated if there is more than one.
     90 Protocol_Description: Identification Protocol         #Protocol Abbreviation Spelled out
     91 
     92 Entry_1:
     93   Name: Notes
     94   Description: Notes for Ident
     95   Note: |
     96     The Ident Protocol is used over the Internet to associate a TCP connection with a specific user. Originally designed to aid in network management and security, it operates by allowing a server to query a client on port 113 to request information about the user of a particular TCP connection.
     97 
     98     https://book.hacktricks.wiki/en/network-services-pentesting/113-pentesting-ident.html
     99 
    100 Entry_2:
    101   Name: Enum Users
    102   Description: Enumerate Users
    103   Note: apt install ident-user-enum    ident-user-enum {IP} 22 23 139 445 (try all open ports)
    104 ```
    105 
    106 ## References
    107 
    108 - [1] [ident-user-enum - pentestmonkey](https://github.com/pentestmonkey/ident-user-enum)
    109 - [2] [RFC 1413 — Identification Protocol](https://www.rfc-editor.org/rfc/rfc1413.html)
    110 - [3] [Nmap NSE documentation — `auth-owners`](https://nmap.org/nsedoc/scripts/auth-owners.html)