Script nntp-ntlm-info

Script types: portrule
Categories: default, discovery, safe

Script Summary

This script enumerates information from remote NNTP services with NTLM authentication enabled.

Sending an MS-NNTP NTLM authentication request with null credentials will cause the remote service to respond with a NTLMSSP message disclosing information to include NetBIOS, DNS, and OS build version.

Script Arguments

smbdomain, smbhash, smbnoguest, smbpassword, smbtype, smbusername

See the documentation for the smbauth library.

Example Usage

nmap -p 119,433,563 --script nntp-ntlm-info <target>

Script Output

119/tcp   open     nntp
| nntp-ntlm-info:
|   Target_Name: ACTIVENNTP
|   NetBIOS_Domain_Name: ACTIVENNTP
|   NetBIOS_Computer_Name: NNTP-TEST2
|   DNS_Domain_Name:
|   DNS_Computer_Name:
|   DNS_Tree_Name:
|_  Product_Version: 6.1.7601



  • Justin Cacak

License: Same as Nmap--See