Server exploitation

Every SMTP port is backed by a mail transfer agent, and the MTA, not the protocol, carries the remote-code-execution surface. Exim, Sendmail, and Postfix have very different histories: Exim has suffered string-expansion and command-handling flaws reachable over a plain SMTP conversation, Sendmail's long lineage includes header-parsing memory corruption and the classic command backdoors, and Postfix's core is hardened so its exploitation runs through the programs it hands mail to. The first move is always to name the MTA and pin its version, because the right exploit is version-specific and the wrong one just closes the connection.

Fingerprint and route#

bash
# the 220 banner usually names the MTA and often the version
nc mail.victim.com 25
# 220 mail.victim.com ESMTP Postfix (Ubuntu)
# 220 mx.victim.com ESMTP Exim 4.92 Mon, 06 Oct 2026 ...
# 220 host.victim.com ESMTP Sendmail 8.14.4/8.14.4; ...
# 220 EXCH01.victim.com Microsoft ESMTP MAIL Service ready ...
nmap -p25 -sV --script smtp-commands mail.victim.com     # confirms product + version

Read the banner string and route:

  • Exim <version> to Exim.
  • Sendmail 8.x to Sendmail.
  • ESMTP Postfix to Postfix, where the value is the integration layer (filters, aliases, transports).
  • Microsoft ESMTP is Exchange's transport; take it to Exchange, not here.

Banners are editable, so corroborate with nmap -sV and with behavioral tells (Exim's ${...} handling, Sendmail's $ macro responses) before committing to a payload.

Pages#

  • Exim: string-expansion RCE in the deliver/ACL path and the 21Nails cluster.
  • Sendmail: header-parse memory corruption, the DEBUG/WIZ backdoors, and local set-uid vectors.
  • Postfix: exploitation through bash-based filters (Shellshock over SMTP) and pipe/local transport abuse.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more