IDENT-USER-ENUM
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
ident-user-enum queries the ident (auth) service (port 113) to determine the owner of a TCP connection. It can enumerate usernames on systems running the ident/auth daemon by checking which user owns processes bound to open ports.
BASIC USAGE#
ident-user-enum <target> <port1> [port2] [port3] ...
# Query ident for port owners
OPTIONS#
ident-user-enum <target> <ports> # Target IP and ports to check
EXAMPLES#
# Check who owns the SSH service ident-user-enum 192.168.1.1 22 # Check multiple service ports ident-user-enum 192.168.1.1 22 80 443 25 21 # Check common service ports ident-user-enum 192.168.1.1 22 25 80 110 143 443 993 995 # Check all common ports ident-user-enum 192.168.1.1 21 22 23 25 53 80 110 111 135 139 143 443 445 993 995 1433 3306 3389 5432 8080
WORKFLOW#
# 1. First scan for open ports with nmap nmap -sS -p- <target> # 2. Then enumerate users on open ports ident-user-enum <target> <port1> <port2> ... # 3. Use discovered usernames for further attacks
INTERPRETING RESULTS#
# Output format: # <target>:<port> <username> # # Example: # 192.168.1.1:22 root # 192.168.1.1:80 www-data # 192.168.1.1:25 postfix # # "ERROR" = ident service not running or blocked # "NO-USER" = no user found for that port
PREREQUISITES#
# Target must be running identd (port 113) # Verify with: nmap -sV -p 113 <target> # Common ident daemons: # - oidentd # - pidentd # - ident2 # - nullidentd (returns fake info)
NOTES#
- Ident service (RFC 1413) runs on TCP port 113 - Many modern systems do not run ident - Can reveal service account usernames - Useful for mapping services to user accounts - Perl-based tool - Requires target to have identd running and accessible - Some ident daemons return fake/random usernames - Works best on older Unix/Linux systems