Here are the results for our first monthly E-Mail Server Survey taken in the latter part of December, 2002. The process used to obtain the results was:
Check random internet addresses for open port 25 (SMTP).
Connect (TCP) to the open port
Record banner
send "EHLO my.host.name"
Record EHLO response
send "QUIT"
Using Nmap, attempt to derive operating system guess and uptime data.
Load the results into a SQL database for data analysis.
This month's sample found 4096 (64^2) open SMTP ports. Many of the responders were .mil (US Military) sites which basically said "go away" which begs the question of why they accepted our connection in the first place!
Total of 2841 servers providing OS information via fingerprints.
Percentages shown are out of the top ten total, not the total hosts examined.
In groupings, version numbers were ignored but shown on drill-down pages.
qmail does not appear probably because it has ambiguous banner.
Total of 1837 servers gave unambiguous answers in banner line.
Percentages shown are out of the top ten total, not the total hosts examined.
In groupings, version numbers were ignored but shown on drill-down pages.
smap does not provide a version in the banner, thus no drill-down.
Uptime Report (in days) for Top Ten Operating Systems
Operating System
Average
# Reporting
Solaris
112.224
129
Irix
109.494
80
Linux
77.176
1068
BSDI
64.133
84
FreeBSD
47.974
87
AIX
29.066
44
Mac OS
25.995
16
HP-UX
22.779
4
NetBSD
17.223
1
All
69.611
1923
No data was reported for Microsoft Windows and others.
Based on results of past surveys (see References) it appears the Sendmail, while still the 900 lb. gorilla, has lost significant market share to a number of different contenders.
Future Plans
Next month - increase the sample size by a factor of 4. (16384 or 128^2)
Issue HELP command to better ascertain what software is running.
Show statistics for Open, Closed and Filtered ports/IPs.
The information contained herein comes with no guarantee of accuracy.
The images, graphs, tables and all other textual data on this page is copyrighted and may not be used in Web pages, electronic, or written publications without the express written permission of Credentia.