Protocols

The mail protocols are attacked at the running service. SMTP moves mail between servers (25) and accepts authenticated submission (587, 465); IMAP (143, 993) and POP3 (110, 995) hand a mailbox to a client. Each exposes the same recurring questions: can you enumerate accounts, relay or spray against it, strip its transport security, and is the server software itself exploitable.

Triage#

bash
nmap -sV -p25,110,143,465,587,993,995 --script \
  smtp-commands,smtp-open-relay,imap-capabilities,pop3-capabilities <target>
# read the banner to identify the daemon, then route to the matching page
printf 'EHLO x\r\nQUIT\r\n' | nc <target> 25     # advertised verbs: AUTH, STARTTLS, VRFY, SIZE

A 25/587/465 service routes to SMTP; a 143/993 service to IMAP; a 110/995 service to POP3. The banner (Postfix, Exim, Sendmail, Dovecot, Cyrus) also decides the server-exploitation path inside each.

Subtopics#

  • SMTP: user enumeration, open relay, authentication, STARTTLS downgrade, SMTP smuggling, and mail-transfer-agent exploitation.
  • IMAP: enumeration, authentication, mailbox access, and server exploitation.
  • POP3: enumeration, authentication, mailbox access, and server exploitation.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more