As part of any post exploitation in a security auditing or testing engagement you will want to gather as much info as you want about the victim to be able to target your next victim in the chain.
Having said that sometimes you stumble upon strange files, encrypted data, and network traffic that you don’t know what to do with it. One of these was an .sdf file related to hmailserver. The last is an open source mail server, you can read more about it here.
When gaining access to this server you will want to read this file:
1 |
C:\Program Files\hMailServer\Bin\hMailServer.ini |
A sample output would look something like this:
1 2 3 4 5 6 7 8 9 |
Recent Comments