Hello, My Youtube Friends. :D
Digiboy16 Back. :D
in their Ethical hacking and Infosec channel every weekend
Cyber_Security_Environment
Today we have a super special Chapter.
Today we going to analyze SMTP packets
Let's Get started.
We have a previously captured capture.
We have all the packets about SMTP
The first step is we have our Host
with the IP address 192.168.0.12
and the server with 192.168.0.13
Basically there are two virtual machines.
vmware virtual machines, with our source and destination
The first three packets are the three way handshake
SYN, SYN ACK, ACK
After the Three way handshake started
start the server giving the server information
Here's the SMTP, show's the SMTP information
The version and the date
Here we have the 25 PORT that's the SMTP port. That's the destination port about our customer.
is 1713
Later the next one is an Extended hello EHLO
to the next one server
and that's the command
And later this continue verifying the SMTP parameters
Here's the code 250 Indicating the OK code.
With different parameters.
After the server verify the parameters, the customer start with the MAIL FROM
who's the sender
martin.tor@4salet.com
Later the server is with the 250 code. Indicating everything is ok
The next one is the reception to. who is the destination.
in this case is bert.manly@five8nine.com
Later send the 250 CODE indicating the OK code.
Here we go to the DATA section, that is the message to the destination
the server indicates to the customer that start with a code and finish with the same code.
as we can see here
After the message is done, the DATA is fragmented, in this case is 593 bytes
The next one packet is an ACK packet indicating everything is ok
later appear a IMF packet, Internet message format
The message ID
indicating the from and the destination.
and the Subject with the encoding subject
and many other information
and everything was in text plain
and a little bit server information
Later everything was OK with the IMF protocol.
the next step is the verification step.
that everything is OK with the 250 code.
and to finish is with the QUIT code from the customer to finish everything.
and the next one is from the server to close the session.
and the TCP packets with the FIN ACK, ACK
in both sides Customer and server.
That's everything for today.
See you Next Weekend, BYE!
If you Liked the video, Give us a Like. And Don't Forget Subscribe.
Không có nhận xét nào:
Đăng nhận xét