> For the complete documentation index, see [llms.txt](https://n3mosec.gitbook.io/pentest-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://n3mosec.gitbook.io/pentest-notes/notes/methodologies-and-tools/scanning-and-enumeration/port-25-smtp.md).

# Port 25 - SMTP

A lot of times these will be locked down, but maybe we'll be lucky.

**Generic Connection:**

```
nc -nv 10.11.1.217 25
```

NB: Nmap -sC will typically show the allowed commands.

**Testing:**

* **Enumerate Users:**
  * VRFY username (checks if username exists)
  * EXPN username (verifies if username is valid)
* **Mail Spoofing:**
  * HELO something MAIL FROM: fake\_address RCPT TO:valid\_mail\_account DATA . QUIT
* **Mail Relay Test:**
  * HELO something
    * Identical to/from - mail from: \<nobody\@domain> rcpt to: \<nobody\@domain>&#x20;
    * Unknown domain - mail from: \<user\@unknown\_domain>
    * Domain not present - mail from: \<user\@localhost>
    * Domain not supplied - mail from: \<user>
    * Source address omission - mail from: <> rcpt to: \<nobody\@recipient\_domain>
    * Use IP address of target server - mail from: \<user\@IP\_Address> rcpt to: \<nobody\@recipient\_domain>
    * Use double quotes - mail from: \<user\@domain> rcpt to: <"user\@recipent-domain">
    * User IP address of the target server - mail from: \<user\@domain> rcpt to: \<nobody\@recipient\_domain@\[IP Address]>
    * Disparate formatting - mail from: \<user@\[IP Address]> rcpt to: <@domain:nobody\@recipient-domain>
    * Disparate formatting2 - mail from: \<user@\[IP Address]> rcpt to: \<recipient\_domain!nobody@\[IP Address]>
