From b03215f0636358e0afd0b9e424cf4c3f95e17f63 Mon Sep 17 00:00:00 2001 From: Tom Sellers Date: Mon, 4 Dec 2017 09:01:02 -0600 Subject: [PATCH 1/9] smtp_banners update - data from 2017.11.30 --- xml/smtp_banners.xml | 292 +++++++++++++++++++++++++++++++++++-------- 1 file changed, 237 insertions(+), 55 deletions(-) diff --git a/xml/smtp_banners.xml b/xml/smtp_banners.xml index 27be9498..35f48fb1 100644 --- a/xml/smtp_banners.xml +++ b/xml/smtp_banners.xml @@ -69,28 +69,43 @@ The system or service fingerprint with the highest certainty overwrites the othe http://www.argosoft.com/applications/mailserver/ Example: 220 ArGoSoft Mail Server, Version 1.4 (1.4.0.3) + + + + - + ArGoSoft Mail, freeware version example.com ArGoSoft Mail Server Freeware, Version 1.8 (1.8.8.8) + ArGoSoft Mail Server Freeware, Version 1.8 (1.8.8.8) + + + + - + ArGoSoft Mail, Pro version ArGoSoft Mail Server Pro for WinNT/2000, Version 1.61 (1.6.1.8) ArGoSoft Mail Server Pro for WinNT/2000/XP, Version 1.8 (1.8.9.5) + foo.bar ArGoSoft Mail Server Pro for WinNT/2000/XP, Version 1.8 (1.8.9.5) + + + + - + + @@ -261,12 +276,14 @@ The system or service fingerprint with the highest certainty overwrites the othe - + Microsoft IIS builtin SMTP service, or Microsoft Exchange Server (they are differentiated from each other in smtp-iis.clp) + Microsoft ESMTP MAIL Service, Version: 5.0.2195.5329 ready Thu, 30 Nov 2017 11:40:25 +0200 foo Microsoft ESMTP MAIL Service, Version: 6.0.3790.4675 ready at Wed, 21 Jul 2010 19:04:24 -0700 + Microsoft ESMTP MAIL Service, Version: 6.0.2600.5512 ready at Thu, 30 Nov 2017 18:22:40 +0900 @@ -286,12 +303,14 @@ The system or service fingerprint with the highest certainty overwrites the othe - + Exim with version string and optional timestamp foo.bar ESMTP Exim 4.89 " - foo.bar, ESMTP EXIM 4.83" - foo.bar ESMTP Exim 4.84_2 " + foo.bar, ESMTP EXIM 4.83 + foo.bar ESMTP Exim 4.84_2 + foo.bar ESMTP Exim 4.90_RC3 Thu, 30 Nov 2017 03:52:16 -0700 foo.bar ESMTP Exim 4.89-122312 Thu, 16 Nov 2017 10:33:38 +0200 + foo.bar ESMTP (Exim 4.87) Thu, 30 Nov 2017 03:25:58 -0800 foo.bar ESMTP Exim 4.80 Thu, 16 Nov 2017 01:04:30 -0800 foo.bar ESMTP Exim 3.12 #1 Wed, 31 Jan 2001 15:47:23 +1100 foo.bar ESMTP Exim 4.89 #1 Thu, 16 Nov 2017 04:55:31 -0500 We do not authorize the use of this system to transport unsolicited, and/or bulk e-mail. @@ -328,10 +347,11 @@ The system or service fingerprint with the highest certainty overwrites the othe - + Exim without version string and with optional timestamp foo.bar ESMTP Exim foo.bar ESMTP Exim Thu, 16 Nov 2017 01:11:30 -0800 + foo.bar ESMTP Exim #1 Thu, 30 Nov 2017 05:31:32 -0500 @@ -476,12 +496,32 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Simple MailEnable - example.com ESMTP MailEnable Service, Version: 1.8-- ready at 05/20/15 08:50:22 + + MailEnable - Simple + ESMTP MailEnable Service, Version: 9.53 + + + + - - + + + + + + + + MailEnable - Complex + foo.bar ESMTP MailEnable Service, Version: 1.8-- ready at 05/20/15 08:50:22 + foo.bar ESMTP MailEnable Service, Version: 9.53-9.53- ready at 11/30/17 00:57:37 + foo.bar ESMTP MailEnable Service, Version: 9.00--9.00 ready at 11/30/17 09:30:34 + + + + + + + @@ -794,23 +834,27 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Lotus Notes 4 SMTP MTA - + Lotus Notes 4 SMTP MTA - + + Lotus Domino SMTP MTA - foo.bar ESMTP Service (Lotus Domino Release 5.0.8) ready at Thu, 16 Nov 2017 18:14:12 +0900 + foo.bar ESMTP Service (Lotus Domino Release 8.5) ready at Thu, 30 Nov 2017 17:01:45 +0800 + foo.bar ESMTP Service (Lotus Domino Release 8.5.3FP6 HF1944) ready at Thu, 30 Nov 2017 17:17:43 +0800 foo.bar ESMTP Service (Lotus Domino Release 5.0.13a) ready at Thu, 16 Nov 2017 17:47:42 +0800 - foo.bar ESMTP Service (Lotus Domino Release 7.0.4) ready at Thu, 16 Nov 2017 18:28:36 +0900 + foo.bar ESMTP Service (Lotus Domino Release 7.0.4) ready at Thu, 16 Nov 2017 18:28:36 +0900 foo.bar ESMTP Service (Lotus Domino Release 8.0.2FP2) ready at Thu, 16 Nov 2017 02:17:33 -0700 foo.bar ESMTP Service (Lotus Domino Release 8.5.3) ready at Thu, 16 Nov 2017 17:52:21 +0800 - + ESMTP Service (Lotus Domino Release 7.0) ready at Thu, 30 Nov 2017 17:00:41 +0800 + @@ -818,6 +862,19 @@ The system or service fingerprint with the highest certainty overwrites the othe + + IBM Domino SMTP MTA + foo.bar ESMTP Service (IBM Domino Release 9.0.1FP8 HF475) ready at Thu, 30 Nov 2017 17:55:48 +0900 + foo.bar ESMTP Service (IBM Domino Release 9.0.1) ready at Thu, 30 Nov 2017 10:12:26 +0100 + ESMTP Service (IBM Domino Release 9.0.1FP8) ready at Thu, 30 Nov 2017 13:51:59 -0800 + + + + + + + + Lotus Domino 5 SMTP MTA @@ -1240,9 +1297,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - sendmail on debian - + Sendmail on Debian foo.bar.com ESMTP Sendmail 8.11.0/8.9.3/Debian 8.9.3-21; Sun, 29 Jul 2001 19:51:00 -0700 @@ -1257,11 +1312,108 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - Sendmail for Ubuntu - - foo.bar.com ESMTP Sendmail 8.13.5.20060308/8.13.5/Debian-3ubuntu1.1; Fri, 24 Jul 2009 01:41:21 -0700; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + + Sendmail on Debian 7.x (wheezy) + foo.bar.com ESMTP Sendmail 8.14.4/8.14.4/Debian-4+wheezy1; Thu, 30 Nov 2017 10:33:05 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + foo.bar.com ESMTP Sendmail 8.14.4/8.14.4/Debian-4+deb7u1; Thu, 30 Nov 2017 11:00:33 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + + + + + + + + + + + + + + + Sendmail on Debian 8.x (jessie) + foo.bar.com ESMTP Sendmail 8.14.4/8.14.4/Debian-8+deb8u2; Thu, 30 Nov 2017 10:25:48 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + + + + + + + + + + + + + + + Sendmail on Debian 5.x (lenny) + foo.bar.com ESMTP Sendmail 8.14.3/8.14.3/Debian-5+lenny1; Thu, 30 Nov 2017 12:29:40 +0300; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + + + + + + + + + + + + + + + Sendmail on Debian 4.x (etch) + foo.bar.com ESMTP Sendmail 8.13.8/8.13.8/Debian-3+etch1; Thu, 30 Nov 2017 10:28:23 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + + + + + + + + + + + + + + + Sendmail on Debian 3.1 (sarge) + foo.bar.com ESMTP Sendmail 8.13.4/8.13.4/Debian-3sarge1; Thu, 30 Nov 2017 10:55:47 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + + + + + + + + + + + + + + + Sendmail on Debian patch only + foo.bar.com ESMTP Sendmail 8.15.2/8.15.2/Debian-3; Thu, 30 Nov 2017 10:55:50 +0200; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + foo.bar.com ESMTP Sendmail 8.14.3/8.14.3/Debian-9.4; Thu, 30 Nov 2017 10:11:54 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + foo.bar.com ESMTP Sendmail 8.14.2/8.14.2/Debian-2build1; Thu, 30 Nov 2017 04:09:50 -0600; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + + + + + + + + + + + + + + Sendmail on Ubuntu + foo.bar.com ESMTP Sendmail 8.13.5.20060308/8.13.5/Debian-3ubuntu1.1; Fri, 24 Jul 2009 01:41:21 -0700; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + foo.bar.com ESMTP Sendmail 8.14.4/8.14.4/Debian-4.1ubuntu1; Thu, 30 Nov 2017 11:00:30 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] @@ -1326,27 +1478,14 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - sendmail where both daemon and config file are patched - - foo.bar.com ESMTP Sendmail 8.9.3+3.4W/8.9.3+3.4W; Tue, 30 Jan 2001 20:40:09 -0500 (EST) - - - - - - - - - - - sendmail where neither daemon nor config file are patched, with and without timezone - - example.com ESMTP Sendmail 8.8.8/8.8.9; Wed, 21 Nov 2001 23:39:07 +0100 (CET) - example.com ESMTP blah Sendmail 8.8.8/8.8.9; Wed, 21 Nov 2001 23:39:07 +0100 (CET) - example.com ESMTP Sendmail 8.10.2/8.10.3; Mon, 10 Sep 2001 08:37:14 -0400 - example.com ESMTP foo-MTA Sendmail 8.13.8/8.13.9; Mon, 18 Apr 2011 08:52:38 -0700 + + Sendmail, no OS, optional timestamp, optional timezone + foo.bar ESMTP Sendmail 8.9.3+3.4W/8.9.3+3.4W; Tue, 30 Jan 2001 20:40:09 -0500 (EST) + foo.bar ESMTP Sendmail 8.12.10/8.12.10; + foo.bar ESMTP Sendmail 8.8.8/8.8.9; Wed, 21 Nov 2001 23:39:07 +0100 (CET) + foo.bar ESMTP blah Sendmail 8.8.8/8.8.9; Wed, 21 Nov 2001 23:39:07 +0100 (CET) + foo.bar ESMTP Sendmail 8.10.2/8.10.3; Mon, 10 Sep 2001 08:37:14 -0400 + foo.bar ESMTP foo-MTA Sendmail 8.13.8/8.13.9; Mon, 18 Apr 2011 08:52:38 -0700 @@ -1516,6 +1655,21 @@ The system or service fingerprint with the highest certainty overwrites the othe + + Ecelerity + 2.0.0 mail ESMTP ecelerity 4.0.0.43760 r(Platform:4.0.0.1) Thu, 30 Nov 2017 05:11:00 -0500 + foo.bar ESMTP ecelerity 3.3.1.44388 r(44388) Thu, 30 Nov 2017 03:10:11 -0700 + foo.bar ESMTP ecelerity 3.6.25.56547 r(Core:3.6.25.0) Thu, 30 Nov 2017 03:17:07 -0600 + foo.bar ESMTP ecelerity 4.2.37.61980 r(:) Thu, 30 Nov 2017 09:58:54 +0000 + + + + + + + + + @@ -1531,7 +1685,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + Seattle Labs SLMail server for Windows NT/2k (v2.7 runs on Win9x) http://serverwatch.internet.com/reviews/mail-slmail.html @@ -1560,6 +1714,25 @@ The system or service fingerprint with the highest certainty overwrites the othe + + + SonicWall Email Security + foo.bar ESMTP SonicWALL (9.0.5.2077) + + + + + + + + PowerMTA + foo.bar (PowerMTA(TM) v3.2r24) ESMTP service ready + + + + + + VOPMail http://www.vircom.com/en/products/vopmail/vopmail.shtml @@ -1645,6 +1818,14 @@ The system or service fingerprint with the highest certainty overwrites the othe + + Lyris ListManager + foo.bar ESMTP Lyris ListManager service ready + + + + + WinRoute Pro, runs on 9x/NT/2k @@ -1690,20 +1871,21 @@ The system or service fingerprint with the highest certainty overwrites the othe - + Some simple PERL SMTP server example.com ESMTP Perl - - - catch all for daemons that have no distinguishing fingerprint whatsoever - + + catch all for daemons that have no distinguishing fingerprint whatsoever example.com ESMTP example.com ESMTP Ready example.com SMTP example.com ESMTP Service ready + ESMTP ready + SMTP Ready + ESMTP READY From fe8e35d1a5c965e93c54a5e745d6cc3a8f3736d8 Mon Sep 17 00:00:00 2001 From: Tom Sellers Date: Mon, 4 Dec 2017 09:36:13 -0600 Subject: [PATCH 2/9] tweak fingerprint name, change insensitive match --- xml/smtp_banners.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/xml/smtp_banners.xml b/xml/smtp_banners.xml index 35f48fb1..e6b64ea2 100644 --- a/xml/smtp_banners.xml +++ b/xml/smtp_banners.xml @@ -1685,7 +1685,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + Seattle Labs SLMail server for Windows NT/2k (v2.7 runs on Win9x) http://serverwatch.internet.com/reviews/mail-slmail.html @@ -1878,7 +1878,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - catch all for daemons that have no distinguishing fingerprint whatsoever + Non-specific banner with optional hostname example.com ESMTP example.com ESMTP Ready example.com SMTP From 3a691c25226b278198091d2afb6f17804383cf4a Mon Sep 17 00:00:00 2001 From: Tom Sellers Date: Mon, 4 Dec 2017 09:46:39 -0600 Subject: [PATCH 3/9] PR cleanup, expand Sendmail descriptions --- xml/smtp_banners.xml | 40 +++++++--------------------------------- 1 file changed, 7 insertions(+), 33 deletions(-) diff --git a/xml/smtp_banners.xml b/xml/smtp_banners.xml index e6b64ea2..efb9e618 100644 --- a/xml/smtp_banners.xml +++ b/xml/smtp_banners.xml @@ -71,7 +71,6 @@ The system or service fingerprint with the highest certainty overwrites the othe - @@ -84,7 +83,6 @@ The system or service fingerprint with the highest certainty overwrites the othe ArGoSoft Mail Server Freeware, Version 1.8 (1.8.8.8) - @@ -99,7 +97,6 @@ The system or service fingerprint with the highest certainty overwrites the othe foo.bar ArGoSoft Mail Server Pro for WinNT/2000/XP, Version 1.8 (1.8.9.5) - @@ -501,7 +498,6 @@ The system or service fingerprint with the highest certainty overwrites the othe ESMTP MailEnable Service, Version: 9.53 - @@ -517,7 +513,6 @@ The system or service fingerprint with the highest certainty overwrites the othe foo.bar ESMTP MailEnable Service, Version: 9.00--9.00 ready at 11/30/17 09:30:34 - @@ -1303,7 +1298,6 @@ The system or service fingerprint with the highest certainty overwrites the othe - @@ -1320,7 +1314,6 @@ The system or service fingerprint with the highest certainty overwrites the othe - @@ -1336,7 +1329,6 @@ The system or service fingerprint with the highest certainty overwrites the othe - @@ -1352,7 +1344,6 @@ The system or service fingerprint with the highest certainty overwrites the othe - @@ -1368,7 +1359,6 @@ The system or service fingerprint with the highest certainty overwrites the othe - @@ -1384,7 +1374,6 @@ The system or service fingerprint with the highest certainty overwrites the othe - @@ -1402,7 +1391,6 @@ The system or service fingerprint with the highest certainty overwrites the othe - @@ -1418,7 +1406,6 @@ The system or service fingerprint with the highest certainty overwrites the othe - @@ -1443,9 +1430,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - unknown - + Sendmail - unknown platform (linuxconf variant) foo.bar.com ESMTP Sendmail 8.9.3/linuxconf; Sun, 29 Jul 2001 22:48:28 -0400 @@ -1459,9 +1444,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - unknown - + Sendmail - unknown platform(Berkley variant) foo.bar.com ESMTP MetaInfo Sendmail 2.5 Build 2630 (Berkeley 8.8.6)/8.8.4; Mon, 30 Jul @@ -1516,9 +1499,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - unknown - + Sendmail - unknown (date in version string variant) mail.foo.bar ESMTP Sendmail 8.11.1 (1.1.2.11/12Jul01-1016AM) Wed, 8 Jan 2003 11:21:22 +0100 (MET) @@ -1552,17 +1533,13 @@ The system or service fingerprint with the highest certainty overwrites the othe - - catch all for other versions of sendmail, no hostname or date - + Sendmail - short banner w/o version, platform, or date. Sendmail ESMTP ready - - catch all for other versions of sendmail - + Sendmail - basic with version and date @@ -1580,16 +1557,13 @@ The system or service fingerprint with the highest certainty overwrites the othe - - catch all for other versions of sendmail - + Sendmail - w/o version or platform, optional date. - - catch all for other versions of sendmail + Sendmail - short banner with hostname From f06a43a7781822db04e10092a0efe5d09eed7850 Mon Sep 17 00:00:00 2001 From: Tom Sellers Date: Fri, 8 Dec 2017 13:16:02 -0600 Subject: [PATCH 4/9] Sendmail tweaking - Rename multiple Sendmail fingerprints with the description of "unknown" to something descriptive. The allows generating more accurate metrics of which FPs matched. Simplification of multiple description lines. - Tuning Sendmail fingerprints regex and ordering. --- xml/smtp_banners.xml | 198 +++++++++++++++---------------------------- 1 file changed, 67 insertions(+), 131 deletions(-) diff --git a/xml/smtp_banners.xml b/xml/smtp_banners.xml index efb9e618..f554ac8b 100644 --- a/xml/smtp_banners.xml +++ b/xml/smtp_banners.xml @@ -1058,9 +1058,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Generic Postfix banner. - + Generic Postfix banner. foo.bar.com ESMTP Postfix @@ -1115,10 +1113,14 @@ The system or service fingerprint with the highest certainty overwrites the othe + + Sendmail - short banner w/o hostname, version, platform, or date. + Sendmail ESMTP ready + + + - - sendmail on HPUX with a PHNE (HP Networking patch) installed - + Sendmail - HP-UX with a PHNE (HP Networking patch) installed foo.bar.com ESMTP Sendmail 8.8.6 (PHNE_14041)/8.7.1; Tue, 6 Feb 2001 10:04:32 -0300 (SAT) @@ -1134,9 +1136,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - sendmail on HPUX - + Sendmail - HP-UX example.com ESMTP Sendmail @(#)Sendmail version 8.13.3 - Revision 1.004:: HP-UX11.31 - 03rd February,2010/8.11.1; Wed, 20 May 2015 23:35:38 GMT @@ -1151,9 +1151,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - sendmail on unixware - + Sendmail - Unixware foo.bar.com ESMTP Sendmail 8.8.7/UW7.1.0 ready at Tue, 6 Feb 2001 16:39:30 -0300 (GMT-0300) @@ -1168,9 +1166,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - sendmail on AIX - + Sendmail - AIX (UCB variant) foo.bar.com ESMTP Sendmail AIX4.2/UCB 8.7; Sun, 29 Jul 2001 22:34:37 -0400 (EDT) @@ -1185,10 +1181,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - sendmail on AIX - - foo.bar.com Sendmail AIX 4.1/UCB 5.64/4.03 ready at Mon, 30 Jul 2001 00:42:21 -0500 + Sendmail - AIX (UCB/ready at variant) + foo.bar Sendmail AIX 4.1/UCB 5.64/4.03 ready at Mon, 30 Jul 2001 00:42:21 -0500 @@ -1203,9 +1197,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - sendmail on AIX - + Sendmail - AIX example.com ESMTP Sendmail AIX4.2/8.7/8.8; Sun, 29 Jul 2001 22:34:37 -0400 (EDT) example.com ESMTP Sendmail AIX5.1/8.11.6p2/8.11.0; Fri, 28 Aug 1970 19:42:05 -0800 @@ -1222,10 +1214,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - sendmail on suse - - foo.bar.com ESMTP Sendmail 8.9.3/8.9.3/SuSE Linux 8.9.3-0.1; Mon, 30 Jul 2001 04:48:54 +0200 + Sendmail - SuSE Linux + foo.bar ESMTP Sendmail 8.9.3/8.9.3/SuSE Linux 8.9.3-0.1; Mon, 30 Jul 2001 04:48:54 +0200 @@ -1240,9 +1230,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - sendmail on Solaris - + Sendmail - Solaris with date (no time offeset variant) foo.bar.com ESMTP Sendmail 8.9.3+Sun/8.9.1; Mon, 30 Jul 2001 02:50:22 GMT @@ -1257,9 +1245,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - sendmail on Solaris - + Sendmail - Solaris with date (ready variant) foo.bar.com ESMTP Sendmail 8.8.8+Sun/8.6.4 ready at Thu, 15 Nov 2000 11:40:32 -0800 (PST) @@ -1273,11 +1259,10 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - sendmail on debian - - foo.bar.com ESMTP Debian Sendmail 8.12.0.Beta7/8.12.0.Beta7/Debian 8.12.0.Beta7-1; Sun, 29 Jul 2001 18:52:20 -0800 + + Sendmail - Debian + foo.bar ESMTP Debian Sendmail 8.12.0.Beta7/8.12.0.Beta7/Debian 8.12.0.Beta7-1; Sun, 29 Jul 2001 18:52:20 -0800 + foo.bar ESMTP Sendmail 8.11.0/8.9.3/Debian 8.9.3-21; Sun, 29 Jul 2001 19:51:00 -0700 @@ -1291,23 +1276,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Sendmail on Debian - foo.bar.com ESMTP Sendmail 8.11.0/8.9.3/Debian 8.9.3-21; Sun, 29 Jul 2001 19:51:00 -0700 - - - - - - - - - - - - - Sendmail on Debian 7.x (wheezy) + Sendmail - Debian 7.x (wheezy) foo.bar.com ESMTP Sendmail 8.14.4/8.14.4/Debian-4+wheezy1; Thu, 30 Nov 2017 10:33:05 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] foo.bar.com ESMTP Sendmail 8.14.4/8.14.4/Debian-4+deb7u1; Thu, 30 Nov 2017 11:00:33 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] @@ -1323,7 +1293,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Sendmail on Debian 8.x (jessie) + Sendmail - Debian 8.x (jessie) foo.bar.com ESMTP Sendmail 8.14.4/8.14.4/Debian-8+deb8u2; Thu, 30 Nov 2017 10:25:48 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] @@ -1338,7 +1308,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Sendmail on Debian 5.x (lenny) + Sendmail - Debian 5.x (lenny) foo.bar.com ESMTP Sendmail 8.14.3/8.14.3/Debian-5+lenny1; Thu, 30 Nov 2017 12:29:40 +0300; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] @@ -1353,7 +1323,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Sendmail on Debian 4.x (etch) + Sendmail - Debian 4.x (etch) foo.bar.com ESMTP Sendmail 8.13.8/8.13.8/Debian-3+etch1; Thu, 30 Nov 2017 10:28:23 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] @@ -1368,7 +1338,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Sendmail on Debian 3.1 (sarge) + Sendmail - Debian 3.1 (sarge) foo.bar.com ESMTP Sendmail 8.13.4/8.13.4/Debian-3sarge1; Thu, 30 Nov 2017 10:55:47 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] @@ -1383,7 +1353,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Sendmail on Debian patch only + Sendmail - Debian patch only foo.bar.com ESMTP Sendmail 8.15.2/8.15.2/Debian-3; Thu, 30 Nov 2017 10:55:50 +0200; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] foo.bar.com ESMTP Sendmail 8.14.3/8.14.3/Debian-9.4; Thu, 30 Nov 2017 10:11:54 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] foo.bar.com ESMTP Sendmail 8.14.2/8.14.2/Debian-2build1; Thu, 30 Nov 2017 04:09:50 -0600; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] @@ -1399,7 +1369,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Sendmail on Ubuntu + Sendmail - Ubuntu foo.bar.com ESMTP Sendmail 8.13.5.20060308/8.13.5/Debian-3ubuntu1.1; Fri, 24 Jul 2009 01:41:21 -0700; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] foo.bar.com ESMTP Sendmail 8.14.4/8.14.4/Debian-4.1ubuntu1; Thu, 30 Nov 2017 11:00:30 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] @@ -1413,9 +1383,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - unknown - + Sendmail - Solaris (SMI variant) foo.bar.com Sendmail SMI-8.6/SMI-SVR4 ready at Sun, 29 Jul 2001 22:58:46 -0400 @@ -1444,7 +1412,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Sendmail - unknown platform(Berkley variant) + Sendmail - MetaInfo foo.bar.com ESMTP MetaInfo Sendmail 2.5 Build 2630 (Berkeley 8.8.6)/8.8.4; Mon, 30 Jul @@ -1462,7 +1430,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Sendmail, no OS, optional timestamp, optional timezone + Sendmail - optional timezone and timestamp, w/o OS foo.bar ESMTP Sendmail 8.9.3+3.4W/8.9.3+3.4W; Tue, 30 Jan 2001 20:40:09 -0500 (EST) foo.bar ESMTP Sendmail 8.12.10/8.12.10; foo.bar ESMTP Sendmail 8.8.8/8.8.9; Wed, 21 Nov 2001 23:39:07 +0100 (CET) @@ -1477,30 +1445,9 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - some old version of sendmail - TODO: figure out which versions this could be - - mail.foo.bar Sendmail ready. - - - - - - - sendmail with daemon version only - - mail.foo.bar ESMTP Sendmail 8.8.8 ready at Tue, 6 Feb 2001 14:37:14 +0100 (CET) - - - - - - - - - Sendmail - unknown (date in version string variant) - mail.foo.bar ESMTP Sendmail 8.11.1 (1.1.2.11/12Jul01-1016AM) Wed, 8 Jan 2003 11:21:22 +0100 (MET) + + Sendmail - with version and date (optional timezone), w/o config version + foo.bar ESMTP Sendmail 8.8.8 ready at Tue, 6 Feb 2001 14:37:14 +0100 (CET) @@ -1509,9 +1456,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - unknown - + Sendmail - revision variant 1 foo.example.com ESMTP Sendmail 8.11.1 - (Revision 1.010)/8.9.3; Sat, 22 Jan 2011 10:08:35 -0500 (EST) @@ -1521,9 +1466,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - unknown - + Sendmail - revision variant 2 foo.example.com ESMTP Sendmail @(#)Sendmail version 8.13.3 - Revision 2.007 - 8 December 2008/8.8.6; Wed, 21 Jul 2010 11:17:01 -0400 (EDT) @@ -1532,12 +1475,6 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Sendmail - short banner w/o version, platform, or date. - Sendmail ESMTP ready - - - Sendmail - basic with version and date @@ -1547,44 +1484,43 @@ The system or service fingerprint with the highest certainty overwrites the othe - - catch all for other versions of sendmail - + Sendmail - with date, w/o version or platform - - Sendmail - w/o version or platform, optional date. + + Sendmail - w/o version or platform, optional date and status string. + foo.bar ESMTP Sendmail ; Thu, 30 Nov 2017 17:50:14 +0900 + foo.bar ESMTP Sendmail; Thu, 30 Nov 2017 17:50:14 +0900 - - Sendmail - short banner with hostname - + + Sendmail - short banner with hostname + foo.bar ESMTP Sendmail ready + foo.bar ESMTP Sendmail ready. + foo.bar ESMTP Sendmail + foo.bar Sendmail ready. - - - catch all for other versions of sendmail - + + Sendmail - with version and date, w/o hostname or platform (semicolon variant) + ESMTP Sendmail 8.13.1/8.13.1; Thu, 30 Nov 2017 01:58:22 -0700 - - - - + + + - - catch all for other versions of sendmail - + Sendmail - unknown platform, variant 1 @@ -1592,25 +1528,25 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - catch all for other versions of sendmail - + + Sendmail - with hostname and date, w/o version or platform + example.com ESMTP Sendmail Wed, 20 May 2015 17:17:56 -0600 + example.com ESMTP Sendmail Wed, 5 Aug 2015 17:40:38 -0400 + + - - - catch all for other versions of sendmail, with a date/time - - example.com ESMTP Sendmail Wed, 20 May 2015 17:17:56 -0600 - example.com ESMTP Sendmail Wed, 5 Aug 2015 17:40:38 -0400 + + Sendmail - unknown (date in version string variant) + mail.foo.bar ESMTP Sendmail 8.11.1 (1.1.2.11/12Jul01-1016AM) Wed, 8 Jan 2003 11:21:22 +0100 (MET) - - + + + From ecd915db59d016d1ad1fb593b0daa7197f388302 Mon Sep 17 00:00:00 2001 From: Tom Sellers Date: Sat, 14 Apr 2018 21:24:25 -0500 Subject: [PATCH 5/9] SMTP: more tuning/tweaking --- xml/smtp_banners.xml | 654 ++++++++++++++----------------------------- 1 file changed, 204 insertions(+), 450 deletions(-) diff --git a/xml/smtp_banners.xml b/xml/smtp_banners.xml index f554ac8b..3b2bf3cd 100644 --- a/xml/smtp_banners.xml +++ b/xml/smtp_banners.xml @@ -52,10 +52,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - AnalogX proxy - http://www.analogx.com/contents/download/network/proxy.htm - + AnalogX proxy http://www.analogx.com/contents/download/network/proxy.htm 192.168.1.1 SMTP AnalogX Proxy 4.15 (Release) ready @@ -64,11 +61,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - ArGoSoft Mail Server is fully functional STMP/POP3/Finger server for Windows 95/98/NT/2000. - http://www.argosoft.com/applications/mailserver/ - Example: 220 ArGoSoft Mail Server, Version 1.4 (1.4.0.3) - + ArGoSoft Mail Server + ArGoSoft Mail Server, Version 1.4 (1.4.0.7) @@ -79,7 +73,7 @@ The system or service fingerprint with the highest certainty overwrites the othe ArGoSoft Mail, freeware version - example.com ArGoSoft Mail Server Freeware, Version 1.8 (1.8.8.8) + foo.bar ArGoSoft Mail Server Freeware, Version 1.8 (1.8.8.8) ArGoSoft Mail Server Freeware, Version 1.8 (1.8.8.8) @@ -105,9 +99,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - AppleShare IP Mail Server - + AppleShare IP Mail Server foo.bar AppleShare IP Mail Server 6.2.1 SMTP Server Ready foo.bar AppleShare IP Mail Server 6.2 SMTP Server Ready @@ -117,9 +109,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - CheckPoint FireWall-1 - + CheckPoint FireWall-1 CheckPoint FireWall-1 secure SMTP server CheckPoint FireWall-1 secure ESMTP server @@ -127,9 +117,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Cisco Pix v4.x - + Cisco Pix v4.x + SMTP/cmap ready________________________________________________________________________ @@ -160,8 +149,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Critical Path (aka InScribe) Messaging Server + Critical Path (aka InScribe) Messaging Server http://www.cp.net/products/inscr_messagingserv_overview.html Runs on Windows NT4/2k, Solaris 2.6, 2.7, and 2.8 Sparc/Intel, SGI IRIX 6.5.3 or later, and AIX @@ -175,22 +163,16 @@ The system or service fingerprint with the highest certainty overwrites the othe - - CSM Internet Mail Scanner SMTP proxy - see http://www.csm-usa.com/product/ims/release.htm - TODO: Some versions return a typo "read." instead of "ready." - use this to fingerprint - example: 220 CSM Internet Mail Scanner SMTP-Gateway ready. - example: 220 CSM Internet Mail Scanner SMTP-Gateway read. - + CSM Internet Mail Scanner SMTP Proxy + CSM Internet Mail Scanner SMTP-Gateway ready. + CSM Internet Mail Scanner SMTP-Gateway read. - - EMWAC Internet Mail Services http://emwac.ed.ac.uk/html/internet_toolchest/ims/ims.htm - example: 220 gabriela.networld.com.ar IMS SMTP Receiver Version 0.83 Ready - + EMWAC Internet Mail Services http://emwac.ed.ac.uk/html/internet_toolchest/ims/ims.htm + foo.bar IMS SMTP Receiver Version 0.83 Ready @@ -212,10 +194,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Microsoft Exchange Server 5.5 and above - (for sure, can't be confused with the IIS builtin SMTP service) - + Microsoft Exchange Server 5.5 and above (for sure, can't be confused with the IIS builtin SMTP service) + foo.bar ESMTP Server (Microsoft Exchange Internet Mail Service 5.5.2653.13) ready @@ -227,10 +207,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Microsoft Exchange Server 5.0 - (for sure, can't be confused with the IIS builtin SMTP service) - + Microsoft Exchange Server 5.0 (for sure, can't be confused with the IIS builtin SMTP service) + foo.bar Microsoft Exchange Internet Mail Service 5.0.1460.8 ready @@ -242,11 +220,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Microsoft Exchange 2007/2010 - (for sure, can't be confused with the IIS builtin SMTP service) - - foo Microsoft ESMTP MAIL Service ready at Wed, 21 Jul 2010 19:04:24 -0700 + Microsoft Exchange 2007/2010 (for sure, can't be confused with the IIS builtin SMTP service) + foo.bar Microsoft ESMTP MAIL Service ready at Wed, 21 Jul 2010 19:04:24 -0700 @@ -257,10 +232,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Microsoft IIS builtin SMTP service, or Microsoft Exchange Server - (they are differentiated from each other in smtp-iis.clp) - + Microsoft IIS builtin SMTP service, or Microsoft Exchange Server (they are differentiated from each other in smtp-iis.clp) + foo.bar Microsoft SMTP MAIL ready at Wed, 29 Nov 2017 23:48:59 +0000 Version: 5.5.1877.197.19 @@ -273,12 +246,11 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - Microsoft IIS builtin SMTP service, or Microsoft Exchange Server + + Microsoft IIS builtin SMTP service, or Microsoft Exchange Server (they are differentiated from each other in smtp-iis.clp) - - Microsoft ESMTP MAIL Service, Version: 5.0.2195.5329 ready Thu, 30 Nov 2017 11:40:25 +0200 + + Microsoft ESMTP MAIL Service, Version: 5.0.2195.5329 ready Thu, 30 Nov 2017 11:40:25 +0200 foo Microsoft ESMTP MAIL Service, Version: 6.0.3790.4675 ready at Wed, 21 Jul 2010 19:04:24 -0700 Microsoft ESMTP MAIL Service, Version: 6.0.2600.5512 ready at Thu, 30 Nov 2017 18:22:40 +0900 @@ -369,31 +341,27 @@ The system or service fingerprint with the highest certainty overwrites the othe - - FTGate mail server, runs on Windows 9x/NT/2k - http://www.ftgate.com - + FTGate mail server, runs on Windows 9x/NT/2k http://www.ftgate.com foo.bar FTGate server ready -attitude [C.o.r.E] - - - TIS FWTK and derivatives + + TIS FWTK and derivatives http://www.tis.com/research/software/ This fingerprint may be ambiguous because other firewalls (like Gauntlet) are derived from TIS + foo.bar SMTP/smap Ready. + - - Novell GroupWise Internet Agent versions 5 and higher - + Novell GroupWise Internet Agent versions 5 and higher foo.bar GroupWise Internet Agent 5.5.1 Ready (C)1993, 1998 Novell, Inc. @@ -402,9 +370,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Novell GroupWise Internet Agent versions 5 and higher, second variant - + Novell GroupWise Internet Agent versions 5 and higher, second variant foo.bar GroupWise Internet Agent 8.0.3 Copyright (c) 1993-2012 Novell, Inc. All rights reserved. Ready foo.bar GroupWise Internet Agent 14.2.1 Copyright 1993-2016 Novell, Inc., a Micro Focus Company. All rights reserved. Ready @@ -414,10 +380,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Novell GroupWise versions below 5 - example: 220 bates.at GroupWise SMTP/MIME Daemon 4.1 v3 Ready (C)1993, 1996 Novell, Inc. - + Novell GroupWise versions below 5 + foo.bar GroupWise SMTP/MIME Daemon 4.1 v3 Ready (C)1993, 1996 Novell, Inc. @@ -425,31 +389,11 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - IBM SMTP server for VM/ESA on IBM S/390 and IBM eserver z/Series 900. - http://www.vm.ibm.com - http://www-1.ibm.com/servers/eserver/zseries/ - http://mitvma.mit.edu/system/vm.html - example: 220 mail.foo.bar running IBM VM SMTP Level 3A0 on Mon, 10 Sep 2001 07:21:54 EDT - example: 220 mail.foo.bar running IBM VM SMTP V2R4 on Mon, 10 Sep 2001 12:23:47 +0100 - - - - - - - - - - - - IBM SMTP server for VM/ESA on IBM S/390 and IBM eserver z/Series 900. - http://www.vm.ibm.com - http://www-1.ibm.com/servers/eserver/zseries/ - http://mitvma.mit.edu/system/vm.html - example: 220 mail.foo.bar ESMTP running IBM VM SMTP V2R4; Mon, 10 Sep 2001 07:24:35 -0400 (EDT) - + + IBM SMTP server for VM/ESA on IBM S/390 and IBM eserver z/Series 900. + foo.bar running IBM VM SMTP Level 640 on Thu, 30 Nov 2017 01:08:59 PDT + foo.bar running IBM VM SMTP Level 3A0 on Mon, 10 Sep 2001 07:21:54 EDT + foo.bar ESMTP running IBM VM SMTP V2R4; Mon, 10 Sep 2001 07:24:35 -0400 (EDT) @@ -472,7 +416,7 @@ The system or service fingerprint with the highest certainty overwrites the othe JAMES SMTP Server - example.com SMTP Server (JAMES SMTP Server 2.3.2) ready Tue, 19 May 2015 00:36:13 +0200 (CEST) + foo.bar SMTP Server (JAMES SMTP Server 2.3.2) ready Tue, 19 May 2015 00:36:13 +0200 (CEST) @@ -480,19 +424,6 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - Mail Max (4 version numbers) - example: 220 MAIL3 (Mail-Max Version 4.2.4.7, Wed, 31 Jan 2001 03:44:35 +0100 WST) ESMTP Mail Server Ready. - - - - - - - - - MailEnable - Simple ESMTP MailEnable Service, Version: 9.53 @@ -522,11 +453,10 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - Mail Max (2 version numbers) - example: 220 WEBB (Mail-Max Version 3.065, Wed, 31 Jan 2001 03:46:11 +0100 WST) ESMTP Mail Server Ready. - + + Mail Max + foo.bar (Mail-Max Version 4.2.4.7, Wed, 31 Jan 2001 03:44:35 +0100 WST) ESMTP Mail Server Ready. + foo.bar (Mail-Max Version 3.073, Thu, 30 Nov 2017 17:24:59 +0800 ) ESMTP Mail Server Ready. @@ -536,9 +466,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Rockliffe MailSite with version (http://www.rockliffe.com) - + Rockliffe MailSite with version (http://www.rockliffe.com) foo.bar MailSite ESMTP Receiver Version 3.4.6.0 Ready foo.bar MailSite SMTP Receiver Version 2.1.7 Ready @@ -548,9 +476,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Rockliffe MailSite without version (http://www.rockliffe.com) - + Rockliffe MailSite without version (http://www.rockliffe.com) foo.bar MailSite SMTP Receiver Ready @@ -558,9 +484,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Rockliffe MailSite without hostname(http://www.rockliffe.com) - + Rockliffe MailSite without hostname(http://www.rockliffe.com) MailSite ESMTP Receiver Version 10.2.0.0 Ready @@ -568,10 +492,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Content Security MAILsweeper for SMTP http://www.contenttechnologies.com/products/msw4smtp/default.asp - example: 220 infotech.at MAILsweeper ESMTP Receiver Version 4.2.1.0 Ready - + Content Security MAILsweeper for SMTP http://www.contenttechnologies.com/products/msw4smtp/default.asp foo.bar MAILsweeper ESMTP Receiver Version 4.2.1.0 Ready @@ -630,6 +551,7 @@ The system or service fingerprint with the highest certainty overwrites the othe MDaemon mail server, with version revision foo.bar ESMTP service ready [1] MDaemon v2.84 R foo.bar ESMTP service ready [1] using MDaemon v3.0.3 R + foo.bar ESMTP service ready [1] MDaemon v2.8.7.0 R @@ -642,49 +564,10 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - MDaemon mail server - 220 foo.bar.com ESMTP service ready [1] MDaemon v2.7 SP5 R - - - - - - - - - - - - - - - - - MDaemon mail server - 220 foo.bar.com ESMTP service ready [1] MDaemon v2.8.7.0 R - - - - - - - - - - - - - - - - - - - MDaemon mail server - 220 foo.bar.com ESMTP service ready [2] (MDaemon v2.7 SP4 R) - + + MDaemon mail server - with service pack + foo.bar ESMTP service ready [1] MDaemon v2.7 SP5 R + foo.bar ESMTP service ready [1] (MDaemon v2.7 SP4 R) @@ -699,10 +582,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - MDaemon mail server - 220 foo.bar.com ESMTP service ready [1] (MDaemon v2.5 rB b1 32-T) - + MDaemon mail server + foo.bar ESMTP service ready [1] (MDaemon v2.5 rB b1 32-T) @@ -718,11 +599,11 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - Merak mail server http://www.icewarp.com/merakmail/ (runs on 2000/NT/9x) - 220 mail.db-list.com ESMTP MERAK 3.00.140; Tue, 24 Jul 2001 21:30:47 -0700 - + + Merak mail server http://www.icewarp.com/merakmail/ (runs on 2000/NT/9x) + foo.bar SMTP Merak 8.0.3; Thu, 30 Nov 2017 20:01:41 +1000 + foo.bar ESMTP Merak 8.0.3; Thu, 30 Nov 2017 12:08:09 +0200 + foo.bar ESMTP MERAK 2.10.284; Thu, 30 Nov 2017 17:55:10 +0800 @@ -732,24 +613,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Atrium's MERCUR SMTP server - http://www.atrium-software.com/pub/support_e.cfm - example: 220 MERCUR SMTP-Server (v3.20.01 KA-0098304) for Windows NT ready at Tue, 6 Feb 2001 21:38:26 +0100 - example: 220 MERCUR SMTP-Server (v3.20.01 KA-0098304) for Windows NT ready at Tue, 6 Feb 2001 21:38:26 +0100 - example: 220 MERCUR SMTP-Server (v3.10.18 KA-0098307) for Windows NT ready at Tue, 6 Feb 2001 18:44:03 +0100 - example: 220 MERCUR SMTP-Server (v3.10.18 KA-0098316) for Windows NT ready at Tue, 6 Feb 2001 15:01:51 +0100 - example: 220 MERCUR SMTP-Server (v3.30.03 KA-0098319) for Windows NT ready at Tue, 6 Feb 2001 19:06:18 +0100 - example: 220 MERCUR SMTP-Server (v3.30.03 KA-5341199) for Windows NT ready at Tue, 6 Feb 2001 18:47:09 +0100 - example: 220 MERCUR SMTP-Server (v3.20.01 AS-0098307) for Windows NT ready at Tue, 6 Feb 2001 15:13:14 +0100 - example: 220 MERCUR SMTP-Server (v3.20.01 AS-0098309) for Windows NT ready at Tue, 6 Feb 2001 16:11:42 +0100 - example: 220 MERCUR SMTP-Server (v3.10.16 AS-7962628) for Windows 95 ready at Tue, 6 Feb 2001 16:37:38 +0100 - example: 220 MERCUR SMTP-Server (v3.10.18 AS-5341186) for Windows NT ready at Tue, 6 Feb 2001 19:27:24 +0100 - example: 220 MERCUR SMTP-Server (v3.30.03 CO-0098319) for Windows NT ready at Tue, 6 Feb 2001 20:45:01 +0100 - example: 220 MERCUR SMTP-Server (v3.30.01 NR-7864330) for Windows NT ready at Tue, 6 Feb 2001 21:31:18 +0100 - example: 220 MERCUR SMTP-Server (v3.30.03 DG-0098304) for Windows NT ready at Tue, 6 Feb 2001 22:52:50 +0100 - example: 220 MERCUR SMTP-Server (v3.20.01 SY-0098318) for Windows NT ready at Tue, 6 Feb 2001 23:26:22 +0100 - + Atrium's MERCUR SMTP server http://www.atrium-software.com/pub/support_e.cfm + MERCUR SMTP-Server (v3.30.09 SA-0000005) for Windows NT ready at Thu, 30 Nov 2017 10:01:06 +0100 @@ -761,9 +626,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Mercury NLM for Netware ( http://www.pmail.com/index.cfm ) - + Mercury NLM for Netware ( http://www.pmail.com/index.cfm ) foo.bar Mercury 1.43 ESMTP server ready. @@ -775,9 +638,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Mercury/32 for Win9x/NT/2000 ( http://www.pmail.com/index.cfm ) - + Mercury/32 for Win9x/NT/2000 ( http://www.pmail.com/index.cfm ) foo.bar Mercury/32 v3.01a SMTP/ESMTP server ready. foo.bar Mercury/32 v3.30 ESMTP server ready. @@ -790,12 +651,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Norton Antivirus for Internet Email Gateways - (note the product changed its name from "Norton Antivirus for Internet Email Gateways" (NAVIEG) to - "Norton Antivirus for Gateways" (NAVGW) as of version 2.1 - example: mailman.laughlin.af.mil SMTP NAVIEG 2.0.1; Sun, 29 Jul 2001 22:02:16 -0500 http://www.symantec.com - + Norton Antivirus for Internet Email Gateways (becomes NAVGW in 2.1) + foo.bar SMTP NAVIEG 2.0.1; Sun, 29 Jul 2001 22:02:16 -0500 http://www.symantec.com @@ -805,10 +662,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Netscape Messaging Server - example: 220 mail.iasmail.net ESMTP service (Netscape Messaging Server 4.15 Patch 2 (built May 30 2000)) - + Netscape Messaging Server - with patch number + foo.bar ESMTP service (Netscape Messaging Server 4.15 Patch 7 (built Sep 12 2001)) @@ -816,10 +671,9 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - Netscape Messaging Server - + + Netscape Messaging Server - w/o patch number + foo.bar ESMTP server (Netscape Messaging Server - Version 3.6) ready Thu, 30 Nov 2017 04:19:10 -0500 @@ -830,6 +684,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Lotus Notes 4 SMTP MTA + foo.bar Lotus SMTP MTA Service Ready @@ -840,15 +695,16 @@ The system or service fingerprint with the highest certainty overwrites the othe named Domino until Dec 1996 w/ v 4.5. Seems to have started being called IBM Domino as of v9.0 on product and in banners. --> - + Lotus Domino SMTP MTA foo.bar ESMTP Service (Lotus Domino Release 8.5) ready at Thu, 30 Nov 2017 17:01:45 +0800 foo.bar ESMTP Service (Lotus Domino Release 8.5.3FP6 HF1944) ready at Thu, 30 Nov 2017 17:17:43 +0800 - foo.bar ESMTP Service (Lotus Domino Release 5.0.13a) ready at Thu, 16 Nov 2017 17:47:42 +0800 + foo.bar ESMTP Service (Lotus Domino Release 5.0.13a) ready at Thu, 16 Nov 2017 17:47:42 +0800 foo.bar ESMTP Service (Lotus Domino Release 7.0.4) ready at Thu, 16 Nov 2017 18:28:36 +0900 foo.bar ESMTP Service (Lotus Domino Release 8.0.2FP2) ready at Thu, 16 Nov 2017 02:17:33 -0700 foo.bar ESMTP Service (Lotus Domino Release 8.5.3) ready at Thu, 16 Nov 2017 17:52:21 +0800 ESMTP Service (Lotus Domino Release 7.0) ready at Thu, 30 Nov 2017 17:00:41 +0800 + foo.bar ESMTP Service (Lotus Domino Release 5.0.1 (Intl)) ready at Thu, 30 Nov 2017 12:38:43 +0300 @@ -870,38 +726,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - Lotus Domino 5 SMTP MTA - example: 220 foo.bar.com ESMTP Service (Lotus Domino Release 5.0a) ready at Wed, 20 Jun 2001 08:59:17 +0200 - - - - - - - - - - - - Lotus Domino 5 SMTP MTA, International product version - example: 220 foo.bar.com ESMTP Service (Lotus Domino Release 5.0.5 (Intl)) ready at Tue, 6 Feb 2001 18:54:23 -0500 - - - - - - - - - - - - Lotus Domino (some early build) - 220 foo.bar.com ESMTP Service (Lotus Domino Build 166.1) ready at Tue, 6 Feb 2001 2 - + Lotus Domino (some early build) foo.bar ESMTP Service (Lotus Domino Build 166.1) ready at Thu, 16 Nov 2017 10:39:22 +0200 foo.bar ESMTP Service (Lotus Domino Build V85_M2_08202008) ready at Thu, 16 Nov 2017 03:57:40 -0500 @@ -912,10 +738,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Lotus Notes 4.x with SMTP MTA add-on - 220 Lotus Notes ESMTP Server X1.0 on RedSox R45 Server/Red Sox/US ready at Fri, 15 Feb 2002 09:46:19 -0800. - + Lotus Notes 4.x with SMTP MTA add-on + Lotus Notes ESMTP Server X1.0 on RedSox R45 Server/Red Sox/US ready at Fri, 15 Feb 2002 09:46:19 -0800. @@ -924,11 +748,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - NTMail http://www.gordano.com - example: 220 lilzmail.liwest.at NTMail (v4.30.0012/NU2182.02.1cf87970) ready for ESMTP transfer - example: 220 pluto.wvwc.edu NTMail (v5.06.0016/NT9445.00.28cc9615) ready for ESMTP transfer - + NTMail http://www.gordano.com + foo.bar NTMail (v7.02.3037/NU1319.01.5b000000) ready for ESMTP transfer @@ -937,16 +758,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - versions 3.x and earlier of NTMail http://www.gordano.com (it was called Internet Shopper's something or other) - example: 220 mail.Networkengineering WindowsNT SMTP Server v3.03.0018/1.aio1/SP ESMTP ready at Wed, 25 Jul 2001 23:03:11 -0400 - example: 220 mars.wvwc.edu WindowsNT SMTP Server v3.03.0018/1.ajhf/SP ESMTP ready at Thu, 29 Oct 1998 18:01:30 -0500 - example: 220 mail.someisp.net WindowsNT SMTP Server v3.03.0017/1.aihl/SP ESMTP ready at Sun, 6 Jun 1999 10:39:30 -0400 - example: 220 nt03s02.switchlink.be WindowsNT SMTP Server v3.03.0014/1.aiss/SP ESMTP ready at Fri, 17 Apr 1998 16:59:04 +0100 - example: 220 www.afsc.org WindowsNT SMTP Server v3.03.0017/1.abkz/SP ESMTP ready at Mon, 2 Oct 2000 11:50:29 -0400 - example: 220 wwmerchant.osopinion.com WindowsNT SMTP Server v3.03.0017/4c.adur/SP ESMTP ready at Fri, 26 Mar 1999 13:20:30 -0700 - example: 220 digital-hoon.tecdm.dmi.co.kr WindowsNT SMTP Server v3.02.07/2c.aaaj ready at Thu, 5 Dec 1996 22:46:12 +0000 - + NTMail - versions 3.x and earlier (it was called Internet Shopper's something or other) + foo.bar WindowsNT SMTP Server v3.03.0018/7.aavn/SP ESMTP ready at Thu, 30 Nov 2017 10:15:31 +0100 @@ -958,10 +771,10 @@ The system or service fingerprint with the highest certainty overwrites the othe Some unknown mail server on OpenVMS - example.com V5.7-ECO4, OpenVMS V8.4 IA64 ready at Wed, 20 May 2015 01:22:32 +0100 (BST) - example.com V5.4-15E, OpenVMS V7.3-2 Alpha ready at Wed, 20 May 2015 01:22:18 +0100 (BST) - example.com UCX V4.2-21I, OpenVMS V6.2 VAX ready at Wed, 20 May 2015 01:15:16 GMT - example.com UCX V4.2-21I, OpenVMS V6.2-1H3 Alpha ready at Wed, 20 May 2015 00:55:37 GMT + foo.bar V5.7-ECO4, OpenVMS V8.4 IA64 ready at Wed, 20 May 2015 01:22:32 +0100 (BST) + foo.bar V5.4-15E, OpenVMS V7.3-2 Alpha ready at Wed, 20 May 2015 01:22:18 +0100 (BST) + foo.bar UCX V4.2-21I, OpenVMS V6.2 VAX ready at Wed, 20 May 2015 01:15:16 GMT + foo.bar UCX V4.2-21I, OpenVMS V6.2-1H3 Alpha ready at Wed, 20 May 2015 00:55:37 GMT @@ -972,7 +785,7 @@ The system or service fingerprint with the highest certainty overwrites the othe A.K.I PMail - example.com ESMTP PMailServer [Free Edition] 1.91; Fri, 22 May 2015 02:04:56 + foo.bar ESMTP PMailServer [Free Edition] 1.91; Fri, 22 May 2015 02:04:56 @@ -981,9 +794,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Postfix (2 version ids, followed by os) - + Postfix (2 version ids, followed by os) @@ -991,20 +802,16 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - Postfix (2 version numbers) - + + Postfix - Std semantic versioning + foo.bar ESMTP Postfix (3.1.4) - - - - Postfix (2 version numbers ) - + + Postfix (2 version numbers ) foo.bar ESMTP Postfix (2.8-20100306) @@ -1013,9 +820,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Postfix (1 version number) - + Postfix (1 version number) @@ -1023,10 +828,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Postfix Ubuntu package. - - foo.bar.com ESMTP Postfix (Ubuntu) + Postfix Ubuntu package. + foo.bar ESMTP Postfix (Ubuntu) @@ -1036,10 +839,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Postfix Debian package. - - foo.bar.com ESMTP Postfix (Debian/GNU) + Postfix Debian package. + foo.bar ESMTP Postfix (Debian/GNU) @@ -1049,45 +850,36 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Generic Postfix banner with amusing comments in parentheses - - foo.bar.com ESMTP Postfix (lol) + Generic Postfix banner with amusing comments in parentheses + foo.bar ESMTP Postfix (lol) - + Generic Postfix banner. - foo.bar.com ESMTP Postfix + foo.bar ESMTP Postfix - + Postfix banner without hostname or version ESMTP Postfix - - - Post.Office (3 version numbers) - - 192.168.1.1 ESMTP server (Post.Office v3.1 release PO205e ID# 0-42000U100L2S100) ready Tue, 6 Feb 2001 19:38:32 +0100 - - - - + + Postfix - generic w/o ESMTP + foo.bar Postfix + + - - - - - - Post.Office lacking word "release" before release tag - + + Post.Office + foo.bar ESMTP server (post.office v3.8.4 release 116 ID# 1001-65749U100L10S0V38) ready Thu, 30 Nov 2017 18:46:24 +0900 + foo.bar ESMTP server (Post.Office v3.1 release PO205e ID# 0-42000U100L2S100) ready Tue, 6 Feb 2001 19:38:32 +0100 @@ -1098,16 +890,14 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Raptor Firewall - example: 220 foo.bar.com Generic SMTP handler - + Raptor Firewall (low confidence) + foo.bar Generic SMTP handler SAP SMTP Server - example.com SAP 8.04(53) ESMTP service ready + foo.bar SAP 8.04(53) ESMTP service ready @@ -1121,7 +911,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - HP-UX with a PHNE (HP Networking patch) installed - foo.bar.com ESMTP Sendmail 8.8.6 (PHNE_14041)/8.7.1; Tue, 6 Feb 2001 10:04:32 -0300 (SAT) + foo.bar ESMTP Sendmail 8.8.6 (PHNE_14041)/8.7.1; Tue, 6 Feb 2001 10:04:32 -0300 (SAT) @@ -1137,7 +927,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - HP-UX - example.com ESMTP Sendmail @(#)Sendmail version 8.13.3 - Revision 1.004:: HP-UX11.31 - 03rd February,2010/8.11.1; Wed, 20 May 2015 23:35:38 GMT + foo.bar ESMTP Sendmail @(#)Sendmail version 8.13.3 - Revision 1.004:: HP-UX11.31 - 03rd February,2010/8.11.1; Wed, 20 May 2015 23:35:38 GMT @@ -1152,7 +942,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - Unixware - foo.bar.com ESMTP Sendmail 8.8.7/UW7.1.0 ready at Tue, 6 Feb 2001 16:39:30 -0300 (GMT-0300) + foo.bar ESMTP Sendmail 8.8.7/UW7.1.0 ready at Tue, 6 Feb 2001 16:39:30 -0300 (GMT-0300) @@ -1167,7 +957,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - AIX (UCB variant) - foo.bar.com ESMTP Sendmail AIX4.2/UCB 8.7; Sun, 29 Jul 2001 22:34:37 -0400 (EDT) + foo.bar ESMTP Sendmail AIX4.2/UCB 8.7; Sun, 29 Jul 2001 22:34:37 -0400 (EDT) @@ -1198,8 +988,8 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - AIX - example.com ESMTP Sendmail AIX4.2/8.7/8.8; Sun, 29 Jul 2001 22:34:37 -0400 (EDT) - example.com ESMTP Sendmail AIX5.1/8.11.6p2/8.11.0; Fri, 28 Aug 1970 19:42:05 -0800 + foo.bar ESMTP Sendmail AIX4.2/8.7/8.8; Sun, 29 Jul 2001 22:34:37 -0400 (EDT) + foo.bar ESMTP Sendmail AIX5.1/8.11.6p2/8.11.0; Fri, 28 Aug 1970 19:42:05 -0800 @@ -1231,7 +1021,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - Solaris with date (no time offeset variant) - foo.bar.com ESMTP Sendmail 8.9.3+Sun/8.9.1; Mon, 30 Jul 2001 02:50:22 GMT + foo.bar ESMTP Sendmail 8.9.3+Sun/8.9.1; Mon, 30 Jul 2001 02:50:22 GMT @@ -1246,7 +1036,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - Solaris with date (ready variant) - foo.bar.com ESMTP Sendmail 8.8.8+Sun/8.6.4 ready at Thu, 15 Nov 2000 11:40:32 -0800 (PST) + foo.bar ESMTP Sendmail 8.8.8+Sun/8.6.4 ready at Thu, 15 Nov 2000 11:40:32 -0800 (PST) @@ -1278,8 +1068,8 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - Debian 7.x (wheezy) - foo.bar.com ESMTP Sendmail 8.14.4/8.14.4/Debian-4+wheezy1; Thu, 30 Nov 2017 10:33:05 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] - foo.bar.com ESMTP Sendmail 8.14.4/8.14.4/Debian-4+deb7u1; Thu, 30 Nov 2017 11:00:33 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + foo.bar ESMTP Sendmail 8.14.4/8.14.4/Debian-4+wheezy1; Thu, 30 Nov 2017 10:33:05 +0100; (No UCE/UBE) logging access from: xyz.foo.bar(OK)-xyz.foo.bar [10.0.0.1] + foo.bar ESMTP Sendmail 8.14.4/8.14.4/Debian-4+deb7u1; Thu, 30 Nov 2017 11:00:33 +0100; (No UCE/UBE) logging access from: xyz.foo.bar(OK)-xyz.foo.bar [10.0.0.1] @@ -1294,7 +1084,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - Debian 8.x (jessie) - foo.bar.com ESMTP Sendmail 8.14.4/8.14.4/Debian-8+deb8u2; Thu, 30 Nov 2017 10:25:48 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + foo.bar ESMTP Sendmail 8.14.4/8.14.4/Debian-8+deb8u2; Thu, 30 Nov 2017 10:25:48 +0100; (No UCE/UBE) logging access from: xyz.foo.bar(OK)-xyz.foo.bar [10.0.0.1] @@ -1309,7 +1099,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - Debian 5.x (lenny) - foo.bar.com ESMTP Sendmail 8.14.3/8.14.3/Debian-5+lenny1; Thu, 30 Nov 2017 12:29:40 +0300; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + foo.bar ESMTP Sendmail 8.14.3/8.14.3/Debian-5+lenny1; Thu, 30 Nov 2017 12:29:40 +0300; (No UCE/UBE) logging access from: xyz.foo.bar(OK)-xyz.foo.bar [10.0.0.1] @@ -1324,7 +1114,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - Debian 4.x (etch) - foo.bar.com ESMTP Sendmail 8.13.8/8.13.8/Debian-3+etch1; Thu, 30 Nov 2017 10:28:23 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + foo.bar ESMTP Sendmail 8.13.8/8.13.8/Debian-3+etch1; Thu, 30 Nov 2017 10:28:23 +0100; (No UCE/UBE) logging access from: xyz.foo.bar(OK)-xyz.foo.bar [10.0.0.1] @@ -1339,7 +1129,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - Debian 3.1 (sarge) - foo.bar.com ESMTP Sendmail 8.13.4/8.13.4/Debian-3sarge1; Thu, 30 Nov 2017 10:55:47 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + foo.bar ESMTP Sendmail 8.13.4/8.13.4/Debian-3sarge1; Thu, 30 Nov 2017 10:55:47 +0100; (No UCE/UBE) logging access from: xyz.foo.bar(OK)-xyz.foo.bar [10.0.0.1] @@ -1354,9 +1144,9 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - Debian patch only - foo.bar.com ESMTP Sendmail 8.15.2/8.15.2/Debian-3; Thu, 30 Nov 2017 10:55:50 +0200; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] - foo.bar.com ESMTP Sendmail 8.14.3/8.14.3/Debian-9.4; Thu, 30 Nov 2017 10:11:54 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] - foo.bar.com ESMTP Sendmail 8.14.2/8.14.2/Debian-2build1; Thu, 30 Nov 2017 04:09:50 -0600; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + foo.bar ESMTP Sendmail 8.15.2/8.15.2/Debian-3; Thu, 30 Nov 2017 10:55:50 +0200; (No UCE/UBE) logging access from: xyz.foo.bar(OK)-xyz.foo.bar [10.0.0.1] + foo.bar ESMTP Sendmail 8.14.3/8.14.3/Debian-9.4; Thu, 30 Nov 2017 10:11:54 +0100; (No UCE/UBE) logging access from: xyz.foo.bar(OK)-xyz.foo.bar [10.0.0.1] + foo.bar ESMTP Sendmail 8.14.2/8.14.2/Debian-2build1; Thu, 30 Nov 2017 04:09:50 -0600; (No UCE/UBE) logging access from: xyz.foo.bar(OK)-xyz.foo.bar [10.0.0.1] @@ -1370,8 +1160,8 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - Ubuntu - foo.bar.com ESMTP Sendmail 8.13.5.20060308/8.13.5/Debian-3ubuntu1.1; Fri, 24 Jul 2009 01:41:21 -0700; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] - foo.bar.com ESMTP Sendmail 8.14.4/8.14.4/Debian-4.1ubuntu1; Thu, 30 Nov 2017 11:00:30 +0100; (No UCE/UBE) logging access from: xyz.example.com(OK)-xyz.example.com [10.0.0.1] + foo.bar ESMTP Sendmail 8.13.5.20060308/8.13.5/Debian-3ubuntu1.1; Fri, 24 Jul 2009 01:41:21 -0700; (No UCE/UBE) logging access from: xyz.foo.bar(OK)-xyz.foo.bar [10.0.0.1] + foo.bar ESMTP Sendmail 8.14.4/8.14.4/Debian-4.1ubuntu1; Thu, 30 Nov 2017 11:00:30 +0100; (No UCE/UBE) logging access from: xyz.foo.bar(OK)-xyz.foo.bar [10.0.0.1] @@ -1384,7 +1174,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - Solaris (SMI variant) - foo.bar.com Sendmail SMI-8.6/SMI-SVR4 ready at Sun, 29 Jul 2001 22:58:46 -0400 + foo.bar Sendmail SMI-8.6/SMI-SVR4 ready at Sun, 29 Jul 2001 22:58:46 -0400 @@ -1399,7 +1189,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - unknown platform (linuxconf variant) - foo.bar.com ESMTP Sendmail 8.9.3/linuxconf; Sun, 29 Jul 2001 22:48:28 -0400 + foo.bar ESMTP Sendmail 8.9.3/linuxconf; Sun, 29 Jul 2001 22:48:28 -0400 @@ -1413,7 +1203,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - MetaInfo - foo.bar.com ESMTP MetaInfo Sendmail 2.5 Build 2630 (Berkeley 8.8.6)/8.8.4; Mon, 30 Jul + foo.bar ESMTP MetaInfo Sendmail 2.5 Build 2630 (Berkeley 8.8.6)/8.8.4; Mon, 30 Jul @@ -1437,7 +1227,6 @@ The system or service fingerprint with the highest certainty overwrites the othe foo.bar ESMTP blah Sendmail 8.8.8/8.8.9; Wed, 21 Nov 2001 23:39:07 +0100 (CET) foo.bar ESMTP Sendmail 8.10.2/8.10.3; Mon, 10 Sep 2001 08:37:14 -0400 foo.bar ESMTP foo-MTA Sendmail 8.13.8/8.13.9; Mon, 18 Apr 2011 08:52:38 -0700 - @@ -1455,9 +1244,9 @@ The system or service fingerprint with the highest certainty overwrites the othe - + Sendmail - revision variant 1 - foo.example.com ESMTP Sendmail 8.11.1 - (Revision 1.010)/8.9.3; Sat, 22 Jan 2011 10:08:35 -0500 (EST) + foo.foo.bar ESMTP Sendmail 8.11.1 - (Revision 1.010)/8.9.3; Sat, 22 Jan 2011 10:08:35 -0500 (EST) @@ -1465,9 +1254,9 @@ The system or service fingerprint with the highest certainty overwrites the othe - + Sendmail - revision variant 2 - foo.example.com ESMTP Sendmail @(#)Sendmail version 8.13.3 - Revision 2.007 - 8 December 2008/8.8.6; Wed, 21 Jul 2010 11:17:01 -0400 (EDT) + foo.foo.bar ESMTP Sendmail @(#)Sendmail version 8.13.3 - Revision 2.007 - 8 December 2008/8.8.6; Wed, 21 Jul 2010 11:17:01 -0400 (EDT) @@ -1475,26 +1264,12 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Sendmail - basic with version and date - - - - - - - - Sendmail - with date, w/o version or platform - - - - - - - + Sendmail - w/o version or platform, optional date and status string. foo.bar ESMTP Sendmail ; Thu, 30 Nov 2017 17:50:14 +0900 foo.bar ESMTP Sendmail; Thu, 30 Nov 2017 17:50:14 +0900 + foo.bar ESMTP Sendmail Ready; Thu, 30 Nov 2017 10:24:14 +0100 + @@ -1519,19 +1294,10 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Sendmail - unknown platform, variant 1 - - - - - - - Sendmail - with hostname and date, w/o version or platform - example.com ESMTP Sendmail Wed, 20 May 2015 17:17:56 -0600 - example.com ESMTP Sendmail Wed, 5 Aug 2015 17:40:38 -0400 + foo.bar ESMTP Sendmail Wed, 20 May 2015 17:17:56 -0600 + foo.bar ESMTP Sendmail Wed, 5 Aug 2015 17:40:38 -0400 @@ -1548,13 +1314,27 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - - - - 220 smtp.foo.bar -- Server ESMTP (Sun Internet Mail Server sims.4.0.2000.10.12.16.25.p8) - + + + Sendmail - unknown platform, variant 1 + + + + + + + + + Sendmail - basic with version and date + + + + + + + + Sun Internet Mail Server + foo.bar -- Server ESMTP (Sun Internet Mail Server sims.4.0.2000.10.12.16.25.p8) @@ -1580,27 +1360,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - - 220 mercury.doc.ntu.ac.uk -- Server ESMTP (Sun Internet Mail Server sims.4.0.1999.06.13.00.20) - - - - - - - - - - - - - Seattle Labs SLMail server for Windows NT/2k (v2.7 runs on Win9x) - http://serverwatch.internet.com/reviews/mail-slmail.html - http://www.seattlelab.com/ - + Seattle Labs SLMail server for Windows NT/2k (v2.7 runs on Win9x) foo.bar Smtp Server SLMail v2.7 Ready ESMTP spoken here foo.bar SMTP Server SLmail 3.2.3113 Ready ESMTP spoken here foo.bar SMTP Server SLmail 5.5.0.4433 Ready ESMTP spoken here @@ -1644,9 +1405,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - VOPMail http://www.vircom.com/en/products/vopmail/vopmail.shtml - + VOPMail http://www.vircom.com/en/products/vopmail/vopmail.shtml foo.bar VOPmail ESMTP Receiver Version 4.0.179.0 Ready @@ -1655,9 +1414,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - VPOP3 Email server: http://www.pscs.co.uk/products/vpop3/index.html - + VPOP3 Email server: http://www.pscs.co.uk/products/vpop3/index.html foo.bar VPOP3 ESMTP Server Ready foo.bar VPOP3 SMTP Server Ready foo.bar VPOP3 SMTP Server access not allowed! @@ -1666,24 +1423,10 @@ The system or service fingerprint with the highest certainty overwrites the othe - - - http://www.mcafeeb2b.com/products/webshield-smtp/default.asp - example:220 smtp.foo.bar WebShield SMTP V4.5 Network Associates, Inc. Ready at Fri Jun 22 02:36:23 2001 - - - - - - - - - - - - http://www.mcafeeb2b.com/products/webshield-smtp/default.asp - example:220 wsigate WebShield SMTP V4.5 MR1 Network Associates, Inc. Ready at Sun Jul 29 22:47:44 2001 - + + McAfee WebShield + foo.bar WebShield SMTP V4.5 MR1a Network Associates, Inc. Ready at Thu Nov 30 09:15:32 2017 + foo.bar WebShield SMTP V4.5 Network Associates, Inc. Ready at Thu Nov 30 09:15:32 2017 @@ -1694,12 +1437,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - McAfee Webshield ASaP is a combination hardware/software platform, - basically consisting of a 1U Linux rackmount box with McAfee's filtering software - http://www.mcafeeb2b.com/services/webshield-asap/faq.asp - example: 220 smtp.foo.bar McAfee WebShield ASaP v1.0.1: Sun, 29 Jul 2001 22:46:18 -0700 - + McAfee Webshield ASaP (bundled hardware / software) + foo.bar McAfee WebShield ASaP v1.0.1: Sun, 29 Jul 2001 22:46:18 -0700 @@ -1713,9 +1452,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - example: 220 smtp.foo.bar McAfee VirusScreen ASaP v1.1: Sun, 20 Jul 2003 09:20:52 -0700 - + McAfee VirusScreen + foo.bar McAfee VirusScreen ASaP v1.1: Sun, 20 Jul 2003 09:20:52 -0700 @@ -1737,10 +1475,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - - WinRoute Pro, runs on 9x/NT/2k - http://www.tinysoftware.com/winpro.php - + WinRoute Pro, runs on 9x/NT/2k http://www.tinysoftware.com/winpro.php foo.bar ESMTP - WinRoute Pro 4.2.4 @@ -1781,18 +1516,37 @@ The system or service fingerprint with the highest certainty overwrites the othe + + Communigate Pro + foo.bar ESMTP CommuniGate Pro 5.3.1 + foo.bar ESMTP CommuniGate Pro 6.2c3 + foo.bar ESMTP CommuniGate Pro 4.3.12. It is you again :-( + + + + + + + + Twisted SMTP server + foo.bar NO UCE NO UBE NO RELAY PROBES ESMTP + + + + + Some simple PERL SMTP server - example.com ESMTP Perl + foo.bar ESMTP Perl Non-specific banner with optional hostname - example.com ESMTP - example.com ESMTP Ready - example.com SMTP - example.com ESMTP Service ready + foo.bar ESMTP + foo.bar ESMTP Ready + foo.bar SMTP + foo.bar ESMTP Service ready ESMTP ready SMTP Ready ESMTP READY From 1d66d42d5864385f528b85011d1e4569f56f0813 Mon Sep 17 00:00:00 2001 From: Tom Sellers Date: Sat, 14 Apr 2018 22:03:25 -0500 Subject: [PATCH 6/9] SMTP: Correct time format --- xml/smtp_banners.xml | 114 +++++++++++++++++++++---------------------- 1 file changed, 57 insertions(+), 57 deletions(-) diff --git a/xml/smtp_banners.xml b/xml/smtp_banners.xml index 3b2bf3cd..333154cf 100644 --- a/xml/smtp_banners.xml +++ b/xml/smtp_banners.xml @@ -240,7 +240,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -259,7 +259,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -286,7 +286,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -297,7 +297,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -311,7 +311,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -324,7 +324,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -336,7 +336,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -397,7 +397,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -422,7 +422,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + MailEnable - Simple @@ -460,7 +460,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -506,7 +506,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -523,7 +523,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -607,7 +607,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -618,7 +618,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -656,7 +656,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -677,7 +677,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -708,7 +708,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -721,7 +721,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -743,7 +743,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -763,7 +763,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -788,7 +788,7 @@ The system or service fingerprint with the highest certainty overwrites the othe foo.bar ESMTP PMailServer [Free Edition] 1.91; Fri, 22 May 2015 02:04:56 - + @@ -882,7 +882,7 @@ The system or service fingerprint with the highest certainty overwrites the othe foo.bar ESMTP server (Post.Office v3.1 release PO205e ID# 0-42000U100L2S100) ready Tue, 6 Feb 2001 19:38:32 +0100 - + @@ -918,7 +918,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -935,7 +935,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -949,7 +949,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -964,7 +964,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -979,7 +979,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -996,7 +996,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1012,7 +1012,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1028,7 +1028,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1043,7 +1043,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1059,7 +1059,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1076,7 +1076,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1091,7 +1091,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1106,7 +1106,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1121,7 +1121,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1136,7 +1136,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1152,7 +1152,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1167,7 +1167,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1181,7 +1181,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1195,7 +1195,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1211,7 +1211,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1228,7 +1228,7 @@ The system or service fingerprint with the highest certainty overwrites the othe foo.bar ESMTP Sendmail 8.10.2/8.10.3; Mon, 10 Sep 2001 08:37:14 -0400 foo.bar ESMTP foo-MTA Sendmail 8.13.8/8.13.9; Mon, 18 Apr 2011 08:52:38 -0700 - + @@ -1239,7 +1239,7 @@ The system or service fingerprint with the highest certainty overwrites the othe foo.bar ESMTP Sendmail 8.8.8 ready at Tue, 6 Feb 2001 14:37:14 +0100 (CET) - + @@ -1249,7 +1249,7 @@ The system or service fingerprint with the highest certainty overwrites the othe foo.foo.bar ESMTP Sendmail 8.11.1 - (Revision 1.010)/8.9.3; Sat, 22 Jan 2011 10:08:35 -0500 (EST) - + @@ -1259,7 +1259,7 @@ The system or service fingerprint with the highest certainty overwrites the othe foo.foo.bar ESMTP Sendmail @(#)Sendmail version 8.13.3 - Revision 2.007 - 8 December 2008/8.8.6; Wed, 21 Jul 2010 11:17:01 -0400 (EDT) - + @@ -1289,7 +1289,7 @@ The system or service fingerprint with the highest certainty overwrites the othe ESMTP Sendmail 8.13.1/8.13.1; Thu, 30 Nov 2017 01:58:22 -0700 - + @@ -1301,7 +1301,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1309,7 +1309,7 @@ The system or service fingerprint with the highest certainty overwrites the othe mail.foo.bar ESMTP Sendmail 8.11.1 (1.1.2.11/12Jul01-1016AM) Wed, 8 Jan 2003 11:21:22 +0100 (MET) - + @@ -1319,7 +1319,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - unknown platform, variant 1 - + @@ -1354,7 +1354,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1430,7 +1430,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1442,7 +1442,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1457,7 +1457,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1487,7 +1487,7 @@ The system or service fingerprint with the highest certainty overwrites the othe ESMTP - WinRoute Pro 4.2.1 Thu, 16 Nov 2017 11:48:15 +0300 - + @@ -1497,7 +1497,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + @@ -1509,7 +1509,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + From c24580c37f6ab13742ecb753c5c386e743359234 Mon Sep 17 00:00:00 2001 From: Tom Sellers Date: Sun, 15 Apr 2018 08:59:47 -0500 Subject: [PATCH 7/9] SMTP: additional products --- xml/smtp_banners.xml | 98 +++++++++++++++++++++++++++++++++----------- 1 file changed, 73 insertions(+), 25 deletions(-) diff --git a/xml/smtp_banners.xml b/xml/smtp_banners.xml index 333154cf..d19e40b6 100644 --- a/xml/smtp_banners.xml +++ b/xml/smtp_banners.xml @@ -713,10 +713,10 @@ The system or service fingerprint with the highest certainty overwrites the othe - + IBM Domino SMTP MTA foo.bar ESMTP Service (IBM Domino Release 9.0.1FP8 HF475) ready at Thu, 30 Nov 2017 17:55:48 +0900 - foo.bar ESMTP Service (IBM Domino Release 9.0.1) ready at Thu, 30 Nov 2017 10:12:26 +0100 + foo.bar ESMTP Service (IBM Domino Release 9.0.1) ready at Thu, 30 Nov 2017 10:12:26 +0100 ESMTP Service (IBM Domino Release 9.0.1FP8) ready at Thu, 30 Nov 2017 13:51:59 -0800 @@ -739,7 +739,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Lotus Notes 4.x with SMTP MTA add-on - Lotus Notes ESMTP Server X1.0 on RedSox R45 Server/Red Sox/US ready at Fri, 15 Feb 2002 09:46:19 -0800. + Lotus Notes ESMTP Server X1.0 on FooBar R45 Server/Foo Bar/US ready at Fri, 15 Feb 2002 09:46:19 -0800. @@ -838,6 +838,17 @@ The system or service fingerprint with the highest certainty overwrites the othe + + Postfix Ubuntu - Mail-in-a-Box package + foo.bar Hi, I'm a Mail-in-a-Box (Ubuntu/Postfix; see https://mailinabox.email/) + + + + + + + + Postfix Debian package. foo.bar ESMTP Postfix (Debian/GNU) @@ -1234,6 +1245,16 @@ The system or service fingerprint with the highest certainty overwrites the othe + + Sendmail - with timezone and timestamp, w/o timezone offset or OS + foo.bar ESMTP Sendmail 8.14.4/8.14.4; Thu, 5 Apr 2018 19:30:58 GMT + + + + + + + Sendmail - with version and date (optional timezone), w/o config version foo.bar ESMTP Sendmail 8.8.8 ready at Tue, 6 Feb 2001 14:37:14 +0100 (CET) @@ -1264,25 +1285,23 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Sendmail - w/o version or platform, optional date and status string. + + Sendmail - with date, w/o version or platform, optional status string. foo.bar ESMTP Sendmail ; Thu, 30 Nov 2017 17:50:14 +0900 foo.bar ESMTP Sendmail; Thu, 30 Nov 2017 17:50:14 +0900 - foo.bar ESMTP Sendmail Ready; Thu, 30 Nov 2017 10:24:14 +0100 - - - - - - - Sendmail - short banner with hostname + foo.bar ESMTP Sendmail Wed, 20 May 2015 17:17:56 -0600 + foo.bar ESMTP Sendmail Ready; Thu, 30 Nov 2017 10:24:14 +0100 + foo.bar ESMTP Sendmail ready at Fri, 6 Apr 2018 04:57:01 +0900 foo.bar ESMTP Sendmail ready foo.bar ESMTP Sendmail ready. foo.bar ESMTP Sendmail foo.bar Sendmail ready. + + + Sendmail - with version and date, w/o hostname or platform (semicolon variant) @@ -1294,16 +1313,6 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Sendmail - with hostname and date, w/o version or platform - foo.bar ESMTP Sendmail Wed, 20 May 2015 17:17:56 -0600 - foo.bar ESMTP Sendmail Wed, 5 Aug 2015 17:40:38 -0400 - - - - - - Sendmail - unknown (date in version string variant) mail.foo.bar ESMTP Sendmail 8.11.1 (1.1.2.11/12Jul01-1016AM) Wed, 8 Jan 2003 11:21:22 +0100 (MET) @@ -1347,7 +1356,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Ecelerity - 2.0.0 mail ESMTP ecelerity 4.0.0.43760 r(Platform:4.0.0.1) Thu, 30 Nov 2017 05:11:00 -0500 + 2.0.0 foo.bar ESMTP ecelerity 4.0.0.43760 r(Platform:4.0.0.1) Thu, 30 Nov 2017 05:11:00 -0500 foo.bar ESMTP ecelerity 3.3.1.44388 r(44388) Thu, 30 Nov 2017 03:10:11 -0700 foo.bar ESMTP ecelerity 3.6.25.56547 r(Core:3.6.25.0) Thu, 30 Nov 2017 03:17:07 -0600 foo.bar ESMTP ecelerity 4.2.37.61980 r(:) Thu, 30 Nov 2017 09:58:54 +0000 @@ -1386,9 +1395,11 @@ The system or service fingerprint with the highest certainty overwrites the othe - + SonicWall Email Security foo.bar ESMTP SonicWALL (9.0.5.2077) + foo.bar ESMTP SonicWall (9.1.1.3113) + @@ -1527,6 +1538,43 @@ The system or service fingerprint with the highest certainty overwrites the othe + + Cellopoint E-mail Firewall + Cellopoint E-mail Firewall v3.9.12 Build 0324 ready + + + + + + + + Kerio Connect ESMTP + foo.bar Kerio Connect 8.0.2 ESMTP ready + foo.bar Kerio Connect 9.2.5 patch 3 ESMTP ready + + + + + + + + + Ma Jian WinWebMail + ESMTP on WinWebMail [3.9.0.7] ready. http://www.winwebmail.com + + + + + + + Tobit Software David + foo.bar Service ready by David.fx (0486) ESMTP Server (Tobit.Software, Germany) + + + + + > + Twisted SMTP server foo.bar NO UCE NO UBE NO RELAY PROBES ESMTP From f686182641e6247fc1e1717be02c1e0697c086e2 Mon Sep 17 00:00:00 2001 From: Tom Sellers Date: Sun, 15 Apr 2018 09:56:31 -0500 Subject: [PATCH 8/9] SMTP: reorder based on frequency --- xml/smtp_banners.xml | 38 +++++++++++++++++++------------------- 1 file changed, 19 insertions(+), 19 deletions(-) diff --git a/xml/smtp_banners.xml b/xml/smtp_banners.xml index d19e40b6..b892b2df 100644 --- a/xml/smtp_banners.xml +++ b/xml/smtp_banners.xml @@ -1527,6 +1527,17 @@ The system or service fingerprint with the highest certainty overwrites the othe + + Kerio Connect ESMTP + foo.bar Kerio Connect 8.0.2 ESMTP ready + foo.bar Kerio Connect 9.2.5 patch 3 ESMTP ready + + + + + + + Communigate Pro foo.bar ESMTP CommuniGate Pro 5.3.1 @@ -1538,6 +1549,14 @@ The system or service fingerprint with the highest certainty overwrites the othe + + Twisted SMTP server + foo.bar NO UCE NO UBE NO RELAY PROBES ESMTP + + + + + Cellopoint E-mail Firewall Cellopoint E-mail Firewall v3.9.12 Build 0324 ready @@ -1547,17 +1566,6 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Kerio Connect ESMTP - foo.bar Kerio Connect 8.0.2 ESMTP ready - foo.bar Kerio Connect 9.2.5 patch 3 ESMTP ready - - - - - - - Ma Jian WinWebMail ESMTP on WinWebMail [3.9.0.7] ready. http://www.winwebmail.com @@ -1575,14 +1583,6 @@ The system or service fingerprint with the highest certainty overwrites the othe > - - Twisted SMTP server - foo.bar NO UCE NO UBE NO RELAY PROBES ESMTP - - - - - Some simple PERL SMTP server foo.bar ESMTP Perl From d914125412a8f486f3080d2217d1969c78991c76 Mon Sep 17 00:00:00 2001 From: Tom Sellers Date: Mon, 16 Apr 2018 08:46:33 -0500 Subject: [PATCH 9/9] SMTP: fp description and date regex tweaks --- xml/smtp_banners.xml | 121 +++++++++++++++++++++---------------------- 1 file changed, 59 insertions(+), 62 deletions(-) diff --git a/xml/smtp_banners.xml b/xml/smtp_banners.xml index b892b2df..2f2d45bf 100644 --- a/xml/smtp_banners.xml +++ b/xml/smtp_banners.xml @@ -24,7 +24,7 @@ The system or service fingerprint with the highest certainty overwrites the othe --> - IMail EVAL version + IMail - EVAL version X1 NT-ESMTP Server foo.bar (IMail 6.06 EVAL 11347-1) @@ -34,7 +34,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - IMail non-EVAL version + IMail - non-EVAL version X1 NT-ESMTP Server foo.bar (IMail 6.06 899085-1) @@ -43,7 +43,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - IMail non-EVAL version, NT-ESMTP at end + IMail - non-EVAL version, NT-ESMTP at end foo.bar (IMail 12.4.2.27 21349-1) NT-ESMTP Server X1 @@ -52,7 +52,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - AnalogX proxy http://www.analogx.com/contents/download/network/proxy.htm + AnalogX proxy (http://www.analogx.com/contents/download/network/proxy.htm) 192.168.1.1 SMTP AnalogX Proxy 4.15 (Release) ready @@ -72,7 +72,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - ArGoSoft Mail, freeware version + ArGoSoft Mail Server - freeware version foo.bar ArGoSoft Mail Server Freeware, Version 1.8 (1.8.8.8) ArGoSoft Mail Server Freeware, Version 1.8 (1.8.8.8) @@ -85,7 +85,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - ArGoSoft Mail, Pro version + ArGoSoft Mail Server - Pro version ArGoSoft Mail Server Pro for WinNT/2000, Version 1.61 (1.6.1.8) ArGoSoft Mail Server Pro for WinNT/2000/XP, Version 1.8 (1.8.9.5) foo.bar ArGoSoft Mail Server Pro for WinNT/2000/XP, Version 1.8 (1.8.9.5) @@ -171,7 +171,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - EMWAC Internet Mail Services http://emwac.ed.ac.uk/html/internet_toolchest/ims/ims.htm + EMWAC Internet Mail Services (http://emwac.ed.ac.uk/html/internet_toolchest/ims/ims.htm) foo.bar IMS SMTP Receiver Version 0.83 Ready @@ -180,7 +180,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Eudora Internet Mail Server + Eudora Internet Mail Server foo.bar running Eudora Internet Mail Server 3.0.2 foo.bar running Eudora Internet Mail Server 2.2 @@ -232,7 +232,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Microsoft IIS builtin SMTP service, or Microsoft Exchange Server (they are differentiated from each other in smtp-iis.clp) + Microsoft IIS builtin SMTP service, or Microsoft Exchange Server (they are differentiated from each other in smtp-iis.clp) - variant 1 foo.bar Microsoft SMTP MAIL ready at Wed, 29 Nov 2017 23:48:59 +0000 Version: 5.5.1877.197.19 @@ -247,9 +247,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Microsoft IIS builtin SMTP service, or Microsoft Exchange Server - (they are differentiated from each other in smtp-iis.clp) - + Microsoft IIS builtin SMTP service, or Microsoft Exchange Server (they are differentiated from each other in smtp-iis.clp) - variant 2 Microsoft ESMTP MAIL Service, Version: 5.0.2195.5329 ready Thu, 30 Nov 2017 11:40:25 +0200 foo Microsoft ESMTP MAIL Service, Version: 6.0.3790.4675 ready at Wed, 21 Jul 2010 19:04:24 -0700 Microsoft ESMTP MAIL Service, Version: 6.0.2600.5512 ready at Thu, 30 Nov 2017 18:22:40 +0900 @@ -266,18 +264,19 @@ The system or service fingerprint with the highest certainty overwrites the othe - Exim without version string or hostname + Exim - without version string or hostname ESMTP Exim - - Exim with version string and optional timestamp + + Exim - with version string and optional timestamp foo.bar ESMTP Exim 4.89 " foo.bar, ESMTP EXIM 4.83 foo.bar ESMTP Exim 4.84_2 foo.bar ESMTP Exim 4.90_RC3 Thu, 30 Nov 2017 03:52:16 -0700 + foo.bar ESMTP Exim 4.89_1b Thu, 05 Apr 2018 21:30:37 +0200 foo.bar ESMTP Exim 4.89-122312 Thu, 16 Nov 2017 10:33:38 +0200 foo.bar ESMTP (Exim 4.87) Thu, 30 Nov 2017 03:25:58 -0800 foo.bar ESMTP Exim 4.80 Thu, 16 Nov 2017 01:04:30 -0800 @@ -292,7 +291,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Exim with digit only version string and optional timestamp + Exim - with digit only version string and optional timestamp foo.bar ESMTP Exim 125302 Thu, 16 Nov 2017 04:55:11 -0500 @@ -303,7 +302,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Exim with version string and optional timestamp (Ubuntu) + Exim - with version string and optional timestamp (Ubuntu) foo.bar ESMTP Exim 4.82 Ubuntu Thu, 16 Nov 2017 11:30:44 +0300 @@ -317,7 +316,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Exim without version string and with optional timestamp + Exim - without version string and with optional timestamp foo.bar ESMTP Exim foo.bar ESMTP Exim Thu, 16 Nov 2017 01:11:30 -0800 foo.bar ESMTP Exim #1 Thu, 30 Nov 2017 05:31:32 -0500 @@ -329,7 +328,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Exim without hostname + Exim - without hostname ESMTP Exim 4.82 Thu, 16 Nov 2017 12:19:22 +0300 ESMTP Exim 4.82 Thu, 16 Nov 2017 11:41:41 +0300 ESMTP Exim 4.89 #1 Thu, 16 Nov 2017 07:32:28 -0200 @@ -341,7 +340,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - FTGate mail server, runs on Windows 9x/NT/2k http://www.ftgate.com + FTGate mail server, runs on Windows 9x/NT/2k (http://www.ftgate.com) foo.bar FTGate server ready -attitude [C.o.r.E] @@ -361,7 +360,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Novell GroupWise Internet Agent versions 5 and higher + Novell GroupWise Internet Agent - versions 5 and higher foo.bar GroupWise Internet Agent 5.5.1 Ready (C)1993, 1998 Novell, Inc. @@ -370,7 +369,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Novell GroupWise Internet Agent versions 5 and higher, second variant + Novell GroupWise Internet Agent - versions 5 and higher, second variant foo.bar GroupWise Internet Agent 8.0.3 Copyright (c) 1993-2012 Novell, Inc. All rights reserved. Ready foo.bar GroupWise Internet Agent 14.2.1 Copyright 1993-2016 Novell, Inc., a Micro Focus Company. All rights reserved. Ready @@ -380,7 +379,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Novell GroupWise versions below 5 + Novell GroupWise - versions below 5 foo.bar GroupWise SMTP/MIME Daemon 4.1 v3 Ready (C)1993, 1996 Novell, Inc. @@ -414,7 +413,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + JAMES SMTP Server foo.bar SMTP Server (JAMES SMTP Server 2.3.2) ready Tue, 19 May 2015 00:36:13 +0200 (CEST) @@ -437,11 +436,12 @@ The system or service fingerprint with the highest certainty overwrites the othe - + MailEnable - Complex foo.bar ESMTP MailEnable Service, Version: 1.8-- ready at 05/20/15 08:50:22 foo.bar ESMTP MailEnable Service, Version: 9.53-9.53- ready at 11/30/17 00:57:37 foo.bar ESMTP MailEnable Service, Version: 9.00--9.00 ready at 11/30/17 09:30:34 + foo.bar ESMTP MailEnable Service, Version: 1.986-- denied access at 04/05/18 16:15:25 @@ -466,7 +466,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Rockliffe MailSite with version (http://www.rockliffe.com) + Rockliffe MailSite - with version (http://www.rockliffe.com) foo.bar MailSite ESMTP Receiver Version 3.4.6.0 Ready foo.bar MailSite SMTP Receiver Version 2.1.7 Ready @@ -476,7 +476,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Rockliffe MailSite without version (http://www.rockliffe.com) + Rockliffe MailSite - without version (http://www.rockliffe.com) foo.bar MailSite SMTP Receiver Ready @@ -484,7 +484,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Rockliffe MailSite without hostname(http://www.rockliffe.com) + Rockliffe MailSite - without hostname (http://www.rockliffe.com) MailSite ESMTP Receiver Version 10.2.0.0 Ready @@ -492,7 +492,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Content Security MAILsweeper for SMTP http://www.contenttechnologies.com/products/msw4smtp/default.asp + Content Security MAILsweeper for SMTP (http://www.contenttechnologies.com/products/msw4smtp/default.asp) foo.bar MAILsweeper ESMTP Receiver Version 4.2.1.0 Ready @@ -501,7 +501,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - MDaemon mail server, with timestamp, unregistered + MDaemon mail server - with timestamp, unregistered foo.bar ESMTP MDaemon 4.0.5 UNREGISTERED; Sat, 06 Oct 2001 09:10:56 +0400 @@ -518,7 +518,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - MDaemon mail server, with timestamp + MDaemon mail server - with timestamp foo.bar ESMTP MDaemon 4.0.2; Sat, 06 Oct 2001 01:46:44 -0500 @@ -534,7 +534,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - MDaemon mail server, without timestamp + MDaemon mail server - without timestamp foo.bar ESMTP MDaemon 3.5.7 ready @@ -548,7 +548,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - MDaemon mail server, with version revision + MDaemon mail server - with version revision foo.bar ESMTP service ready [1] MDaemon v2.84 R foo.bar ESMTP service ready [1] using MDaemon v3.0.3 R foo.bar ESMTP service ready [1] MDaemon v2.8.7.0 R @@ -600,7 +600,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Merak mail server http://www.icewarp.com/merakmail/ (runs on 2000/NT/9x) + Merak mail server - http://www.icewarp.com/merakmail/ (runs on 2000/NT/9x) foo.bar SMTP Merak 8.0.3; Thu, 30 Nov 2017 20:01:41 +1000 foo.bar ESMTP Merak 8.0.3; Thu, 30 Nov 2017 12:08:09 +0200 foo.bar ESMTP MERAK 2.10.284; Thu, 30 Nov 2017 17:55:10 +0800 @@ -613,7 +613,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Atrium's MERCUR SMTP server http://www.atrium-software.com/pub/support_e.cfm + Atrium's MERCUR SMTP server (http://www.atrium-software.com/pub/support_e.cfm) MERCUR SMTP-Server (v3.30.09 SA-0000005) for Windows NT ready at Thu, 30 Nov 2017 10:01:06 +0100 @@ -695,10 +695,11 @@ The system or service fingerprint with the highest certainty overwrites the othe named Domino until Dec 1996 w/ v 4.5. Seems to have started being called IBM Domino as of v9.0 on product and in banners. --> - + Lotus Domino SMTP MTA foo.bar ESMTP Service (Lotus Domino Release 8.5) ready at Thu, 30 Nov 2017 17:01:45 +0800 foo.bar ESMTP Service (Lotus Domino Release 8.5.3FP6 HF1944) ready at Thu, 30 Nov 2017 17:17:43 +0800 + foo.bar ESMTP Service (Lotus Domino Release 8.0.2 FP1 HF82) ready at Thu, 5 Apr 2018 22:03:28 +0200 foo.bar ESMTP Service (Lotus Domino Release 5.0.13a) ready at Thu, 16 Nov 2017 17:47:42 +0800 foo.bar ESMTP Service (Lotus Domino Release 7.0.4) ready at Thu, 16 Nov 2017 18:28:36 +0900 foo.bar ESMTP Service (Lotus Domino Release 8.0.2FP2) ready at Thu, 16 Nov 2017 02:17:33 -0700 @@ -748,7 +749,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - NTMail http://www.gordano.com + NTMail (http://www.gordano.com) foo.bar NTMail (v7.02.3037/NU1319.01.5b000000) ready for ESMTP transfer @@ -783,9 +784,10 @@ The system or service fingerprint with the highest certainty overwrites the othe - + A.K.I PMail foo.bar ESMTP PMailServer [Free Edition] 1.91; Fri, 22 May 2015 02:04:56 + foo.bar ESMTP PMailServer 1.78; Fri, 6 Apr 2018 04:34:11 @@ -794,7 +796,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - Postfix (2 version ids, followed by os) + Postfix - version + build, followed by os @@ -802,16 +804,17 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Postfix - Std semantic versioning + + Postfix - Std semantic versioning, w/ optional parens foo.bar ESMTP Postfix (3.1.4) + foo.bar ESMTP Postfix 2.7.1 - Postfix (2 version numbers ) + Postfix - version + build foo.bar ESMTP Postfix (2.8-20100306) @@ -819,16 +822,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Postfix (1 version number) - - - - - - - - Postfix Ubuntu package. + + Postfix - Ubuntu foo.bar ESMTP Postfix (Ubuntu) @@ -838,8 +833,9 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Postfix Ubuntu - Mail-in-a-Box package + + Postfix - Ubuntu, Mail-in-a-Box package + foo.bar ESMTP Hi, I'm a Mail-in-a-Box (Ubuntu/Postfix; see https://mailinabox.email/) foo.bar Hi, I'm a Mail-in-a-Box (Ubuntu/Postfix; see https://mailinabox.email/) @@ -849,8 +845,8 @@ The system or service fingerprint with the highest certainty overwrites the othe - - Postfix Debian package. + + Postfix - Debian foo.bar ESMTP Postfix (Debian/GNU) @@ -861,21 +857,22 @@ The system or service fingerprint with the highest certainty overwrites the othe - Generic Postfix banner with amusing comments in parentheses + Postfix - generic banner with amusing comments in parentheses foo.bar ESMTP Postfix (lol) - - Generic Postfix banner. + + Postfix - generic banner foo.bar ESMTP Postfix + foo.bar SMTP Postfix - Postfix banner without hostname or version + Postfix - banner without hostname or version ESMTP Postfix @@ -922,7 +919,7 @@ The system or service fingerprint with the highest certainty overwrites the othe Sendmail - HP-UX with a PHNE (HP Networking patch) installed - foo.bar ESMTP Sendmail 8.8.6 (PHNE_14041)/8.7.1; Tue, 6 Feb 2001 10:04:32 -0300 (SAT) + foo.bar ESMTP Sendmail 8.8.6 (PHNE_14041)/8.7.1; Tue, 6 Feb 2001 10:04:32 -0300 (SAT) @@ -936,7 +933,7 @@ The system or service fingerprint with the highest certainty overwrites the othe - + Sendmail - HP-UX foo.bar ESMTP Sendmail @(#)Sendmail version 8.13.3 - Revision 1.004:: HP-UX11.31 - 03rd February,2010/8.11.1; Wed, 20 May 2015 23:35:38 GMT