Separate from guessing credentials, the daemon parsing IMAP for you has its own attack surface. Three implementations dominate: Dovecot (by far the most deployed), Cyrus IMAP (large institutional installs), and Courier (older/legacy hosts). The high-value targets are pre-authentication: code reachable before LOGIN, in the greeting, STARTTLS, or SASL handling. Post-auth bugs still matter for privilege escalation or breaking mailbox isolation once you hold any account. Fingerprint the exact build first, because every one of these is version-gated.
Fingerprint the build#
nc <target> 143
* OK [CAPABILITY ...] Dovecot ready.
nmap -p143,993 -sV <target> # -sV resolves the product/version string
openssl s_client -connect <target>:993 -quiet
a ID NIL # some builds answer ID with name/version
Dovecot's banner is terse by default, so lean on -sV, the ID response where enabled, and side channels (the submission service on 587, the ManageSieve service on 4190) to pin the build. Cyrus and Courier print their product strings in the greeting.
Dovecot#
Dovecot's exposure clusters in its auxiliary services more than core IMAP:
- Submission proxy: Dovecot's built-in submission/LMTP proxying had a flaw where a crafted sequence to the submission service corrupted its handling and could crash or disrupt the proxied session. It is reachable on the submission port and is pre-auth in the sense that the parsing happens during the mail-sending handshake.
- stats /
openssl-style input parsing: Dovecot components that parse structured input (the stats service, and TLS/SNI handling fed into the OpenSSL layer) have historically mishandled malformed input, producing denial of service. These are the "parse untrusted bytes before auth" class; the value is disruption and, where memory is corrupted, a foothold. - Sieve / ManageSieve: once you hold a credential, the ManageSieve service (4190) lets you upload Sieve filter scripts. Sieve's
vnd.dovecot.executeand pipe extensions, where compiled in, run external programs on incoming mail, turning a mailbox credential into command execution on the server. Even without those extensions, the script parser itself is a post-auth attack surface.
# ManageSieve: list capabilities, then upload a filter (post-auth)
nc <target> 4190
"IMPLEMENTATION" "Dovecot Pichia"
"SIEVE" "fileinto reject envelope ... vnd.dovecot.execute"
# the SIEVE line reveals whether the execute/pipe extensions are compiled in
Read the advertised "SIEVE" extension list: the presence of vnd.dovecot.execute or vnd.dovecot.pipe is the signal that a loaded filter can run commands, which is the path worth pursuing from an owned account.
Cyrus IMAP#
Cyrus has the older memory-corruption lineage. Its command and argument parsing (notably the handling of literal lengths and specific commands in older releases) contained buffer overflows reachable by sending an over-long command or literal. The classic cases were in the pre-auth command dispatch, so a crafted command before login could corrupt memory. These are tied to specific older Cyrus releases and are the reason build fingerprinting matters: the trigger exists only on the vulnerable range, and on a patched install the same command is handled cleanly.
Courier#
Courier-IMAP's history is mostly in its authentication and SASL layer and in the surrounding courier-authlib, where input handling flaws produced crashes and, in older builds, worse. Courier appearing in the banner is itself a signal of an aging host likely to be behind on other services too.
Lineage#
The pattern across all three is the same arc: early daemons (Cyrus, Courier, UW-IMAP before them) carried the memory-corruption bugs typical of 1990s/2000s C network services parsing untrusted input pre-auth. Modern Dovecot largely closed that class in core IMAP, and the exposure migrated outward to the auxiliary services (submission, stats, ManageSieve) and to the scripting surface (Sieve) that trades a mailbox credential for execution. When you fingerprint an old Cyrus or Courier, think pre-auth memory corruption; when you fingerprint current Dovecot, think auxiliary-service DoS and post-auth Sieve execution.