githubEdit

enumeration

Check mail server

host -t MX hackthebox.eu
dig mx inlanefreight.htb | grep "MX" | grep -v ";"

Check A record

host -t A mail1.inlanefreight.htb
# SMTP has different commands that can be used to enumerate valid usernames using VRFY,EXPN,RCPT TO.

Enumerate usernames

SMTP

telnet <ip> 25
VRFY root
VRFY www-data
EXPN john
	
MAIL FROM:test@htb.com
It is
RCPT TO:julio
RCPT TO:kate

POP3

Automate username enumeration

smtp-user-enumarrow-up-right

Cloud enumeration

o365sprayarrow-up-right

Password attack (hydra)

Password spraying attack

Open relay attack

Connect with mail server

Last updated