Simple Mail Transfer Protocol (SMTP) Penetration Testing
Enumeration
1) Check for information about the server version, etc
telnet IP 25nc IP 25nmap -sV -p 25 IP2) User enumeration
VRFY admin@domain.comEXPN staff@domain.comTools:
3) Timing-based enumeration
4) SMTP Response Code Analysis
5) Email Headers
SMTP Relay Attacks
Attack process
Tools to detect it:
Brute force attack
Last updated