19.04.2013 Views

2KKUU7ita

2KKUU7ita

2KKUU7ita

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Figure 13-7:<br />

Using<br />

EmailVerify<br />

to verify<br />

an e-mail<br />

address.<br />

Chapter 13: Communication and Messaging Systems<br />

You might get bogus information from your server when performing these two<br />

tests. Some SMTP servers (such as Microsoft Exchange) don’t support the<br />

VRFY and EXPN commands, and some e-mail firewalls simply ignore them or<br />

return false information.<br />

Another way to somewhat automate the process is to use the EmailVerify<br />

program in TamoSoft’s Essential NetTools (www.tamos.com/htmlhelp/<br />

nettools/emailverify.htm). As shown in Figure 13-7, you simply enter<br />

an e-mail address, click Start, and EmailVerify connects to the server and<br />

pretends to send an e-mail.<br />

Yet another way to capture valid e-mail addresses is to use theHarvester<br />

(http://code.google.com/p/theharvester/) to glean addresses via<br />

Google and other search engines. As I outline in Chapter 8, you can download<br />

BackTrack Linux from www.backtrack-linux.org to burn the ISO image to<br />

CD or boot the image directly through VMWare or VirtualBox. In the BackTrack<br />

GUI, simply choose Backtrack➪Information Gathering➪SMTP➪Goog Mail<br />

Enum and enter ./goog-mail.py –d -l 500 –b google, as<br />

shown in Figure 13-8.<br />

259

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!