← All cheat sheets

IDENT-USER-ENUM

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

ident-user-enum queries the ident (auth) service (port 113) to
determine the owner of a TCP connection. It can enumerate usernames
on systems running the ident/auth daemon by checking which user
owns processes bound to open ports.

BASIC USAGE#

ident-user-enum <target> <port1> [port2] [port3] ...
                                 # Query ident for port owners

OPTIONS#

ident-user-enum <target> <ports> # Target IP and ports to check

EXAMPLES#

# Check who owns the SSH service
ident-user-enum 192.168.1.1 22

# Check multiple service ports
ident-user-enum 192.168.1.1 22 80 443 25 21

# Check common service ports
ident-user-enum 192.168.1.1 22 25 80 110 143 443 993 995

# Check all common ports
ident-user-enum 192.168.1.1 21 22 23 25 53 80 110 111 135 139 143 443 445 993 995 1433 3306 3389 5432 8080

WORKFLOW#

# 1. First scan for open ports with nmap
nmap -sS -p- <target>

# 2. Then enumerate users on open ports
ident-user-enum <target> <port1> <port2> ...

# 3. Use discovered usernames for further attacks

INTERPRETING RESULTS#

# Output format:
# <target>:<port>  <username>
#
# Example:
# 192.168.1.1:22   root
# 192.168.1.1:80   www-data
# 192.168.1.1:25   postfix
#
# "ERROR" = ident service not running or blocked
# "NO-USER" = no user found for that port

PREREQUISITES#

# Target must be running identd (port 113)
# Verify with:
nmap -sV -p 113 <target>

# Common ident daemons:
# - oidentd
# - pidentd
# - ident2
# - nullidentd (returns fake info)

NOTES#

- Ident service (RFC 1413) runs on TCP port 113
- Many modern systems do not run ident
- Can reveal service account usernames
- Useful for mapping services to user accounts
- Perl-based tool
- Requires target to have identd running and accessible
- Some ident daemons return fake/random usernames
- Works best on older Unix/Linux systems