π§Email Services Attacks
π― Overview
ποΈ SMTP Attack Methodology
Attack Chain Overview
Service Discovery β User Enumeration β Mail Relay Testing β Credential Attacks β Social EngineeringKey Attack Objectives
π Service Discovery & Enumeration
MX Record Enumeration
HTB Academy MX Record Examples
Cloud vs Custom Mail Servers
Email Service Port Enumeration
HTB Academy Complete Port List
Email Service Ports Reference
Key Information to Extract
π₯ User Enumeration Attacks
SMTP User Enumeration Commands
VRFY Command (HTB Academy Example)
EXPN Command (HTB Academy Example)
RCPT TO Command (HTB Academy Example)
POP3 User Enumeration (HTB Academy Example)
HTB Academy User Enumeration Example
Using smtp-user-enum Tool (HTB Academy Example)
Alternative Enumeration Methods
βοΈ Cloud Enumeration (Office 365)
O365spray Tool (HTB Academy Example)
Validate Office 365 Domain
Office 365 User Enumeration
Cloud Service Enumeration Tools
π¨ Protocol Specific Attacks
Open Mail Relay Exploitation
Understanding Open Relay
HTB Academy Open Relay Detection
HTB Academy Open Relay Exploitation with Swaks
Manual Open Relay Testing
Additional Relay Testing Tools
π Password Attacks
Traditional Email Service Attacks
HTB Academy Hydra Password Spray Example
Additional Hydra Examples
Cloud Service Password Attacks
HTB Academy O365 Password Spraying
Cloud-Specific Tools
π― HTB Academy Lab Scenarios
Scenario 1: SMTP User Enumeration
Scenario 2: SMTP Relay Testing
Scenario 3: Information Gathering
π SMTP Attack Checklist
Discovery & Enumeration
User Enumeration
Exploitation
Post-Exploitation
π‘οΈ Defense & Mitigation
SMTP Server Hardening
Email Security
Monitoring & Detection
π HTB Academy Lab Scenarios
Lab Exercise 1: SMTP User Enumeration
Lab Exercise 2: Email Access & Flag Extraction
Key Lab Learning Points
π§ Tools & Resources
Essential Email Service Tools
Useful Nmap SMTP Scripts
π Related Techniques
π References
Last updated