Description
Simple Mail Transfer Protocol servers (SMTP) are email servers.
Enumeration
nmap --script smtp* -p 25 $IP
nc $IP 25
help
If the RCPT
, VRFY
or EXPN
verbs are enabled, they can be used to enumerate users.
smtp-user-enum -M $VERB -U $USERS_LIST -t $IP
Or using metasploit :
use scanner/smtp/smtp_enum
options
run
Or do it manually :
HELO test.localdomain
MAIL FROM: test@test.localdomain
RCPT TO: $USER@$DOMAIN
VRFY $USER
EXPN $USER