daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-imap.md (8321B)


      1 ---
      2 title: "143,993 - Pentesting IMAP"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-imap.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-imap.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 143,993 - Pentesting IMAP
     14 
     15 ## Internet Message Access Protocol
     16 
     17 The **Internet Message Access Protocol (IMAP)** is designed for the purpose of enabling users to **access their email messages from any location**, primarily through an Internet connection. In essence, emails are **retained on a server** rather than being downloaded and stored on an individual's personal device. This means that when an email is accessed or read, it is done **directly from the server**. This capability allows for the convenience of checking emails from **multiple devices**, ensuring that no messages are missed regardless of the device used.
     18 
     19 IMAP commonly uses two ports:<sup>[[3]](#references)[[4]](#references)</sup>
     20 
     21 - **Port 143** - cleartext IMAP initially, with an optional upgrade to TLS using `STARTTLS`
     22 - **Port 993** - IMAP over implicit TLS
     23 
     24 ```text
     25 PORT    STATE SERVICE REASON
     26 143/tcp open  imap    syn-ack
     27 ```
     28 
     29 ## Banner grabbing
     30 
     31 ```bash
     32 nc -nv <IP> 143
     33 openssl s_client -starttls imap -connect <IP>:143 -crlf -quiet
     34 openssl s_client -connect <IP>:993 -quiet
     35 ```
     36 
     37 ### NTLM Auth - Information disclosure
     38 
     39 If the server supports NTLM auth (Windows) you can obtain sensitive info (versions):
     40 
     41 ```text
     42 root@kali: telnet example.com 143
     43 * OK The Microsoft Exchange IMAP4 service is ready.
     44 >> a1 AUTHENTICATE NTLM
     45 +
     46 >> TlRMTVNTUAABAAAAB4IIAAAAAAAAAAAAAAAAAAAAAAA=
     47 + TlRMTVNTUAACAAAACgAKADgAAAAFgooCBqqVKFrKPCMAAAAAAAAAAEgASABCAAAABgOAJQAAAA9JAEkAUwAwADEAAgAKAEkASQBTADAAMQABAAoASQBJAFMAMAAxAAQACgBJAEkAUwAwADEAAwAKAEkASQBTADAAMQAHAAgAHwMI0VPy1QEAAAAA
     48 ```
     49 
     50 Or **automate** this with Nmap's `imap-ntlm-info` script, which obtains the NTLM challenge and reports fields disclosed by the server.<sup>[[5]](#references)</sup>
     51 
     52 ### [IMAP Bruteforce](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#imap)
     53 
     54 ## Syntax
     55 
     56 IMAP command examples from [this crib sheet](https://donsutherland.org/crib/imap):<sup>[[1]](#references)</sup>
     57 
     58 Only send `LOGIN` credentials after establishing TLS; RFC 9051 requires implementations to protect cleartext passwords against disclosure.<sup>[[3]](#references)</sup>
     59 
     60 ```text
     61 Login
     62     A1 LOGIN username password
     63 Values can be quoted to enclose spaces and special characters. A " must then be escape with a \
     64     A1 LOGIN "username" "password"
     65 
     66 List Folders/Mailboxes
     67     A1 LIST "" *
     68     A1 LIST INBOX *
     69     A1 LIST "Archive" *
     70 
     71 Create new Folder/Mailbox
     72     A1 CREATE INBOX.Archive.2012
     73     A1 CREATE "To Read"
     74 
     75 Delete Folder/Mailbox
     76     A1 DELETE INBOX.Archive.2012
     77     A1 DELETE "To Read"
     78 
     79 Rename Folder/Mailbox
     80     A1 RENAME "INBOX.One" "INBOX.Two"
     81 
     82 List Subscribed Mailboxes
     83     A1 LSUB "" *
     84 
     85 Status of Mailbox (There are more flags than the ones listed)
     86     A1 STATUS INBOX (MESSAGES UNSEEN RECENT)
     87 
     88 Select a mailbox
     89     A1 SELECT INBOX
     90 
     91 List messages
     92     A1 FETCH 1:* (FLAGS)
     93     A1 UID FETCH 1:* (FLAGS)
     94 
     95 Retrieve Message Content
     96     A1 FETCH 2 body[text]
     97     A1 FETCH 2 all
     98     A1 UID FETCH 102 (UID RFC822.SIZE BODY.PEEK[])
     99 
    100 Close Mailbox
    101     A1 CLOSE
    102 
    103 Logout
    104     A1 LOGOUT
    105 ```
    106 
    107 ### Evolution
    108 
    109 ```text
    110 apt install evolution
    111 ```
    112 
    113 ![Syntax - Evolution: apt install evolution](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281033%29.png)
    114 
    115 ### CURL
    116 
    117 Basic navigation is possible with curl's IMAP URL syntax.<sup>[[6]](#references)</sup> The examples below retain `-k` for lab systems with self-signed certificates, but it disables certificate verification. Prefer a trusted CA and omit `-k` on real systems; for port 143, use `--ssl-reqd` to require a successful TLS upgrade.<sup>[[6]](#references)</sup> When documented URL behavior differs from an unusual server, curl's IMAP protocol implementation is also a useful source for confirming the exact command construction and response state machine.<sup>[[7]](#references)</sup>
    118 
    119 1. Listing mailboxes (imap command `LIST "" "*"`)
    120 
    121 ```bash
    122 curl -k 'imaps://1.2.3.4/' --user user:pass
    123 ```
    124 
    125 2. Listing messages in a mailbox (imap command `SELECT INBOX` and then `SEARCH ALL`)
    126 
    127 ```bash
    128 curl -k 'imaps://1.2.3.4/INBOX?ALL' --user user:pass
    129 ```
    130 
    131 The result of this search is a list of message indices.
    132 
    133 It is also possible to provide more complex search terms, for example searching drafts for `password` in the message body:
    134 
    135 ```bash
    136 curl -k 'imaps://1.2.3.4/Drafts?TEXT password' --user user:pass
    137 ```
    138 
    139 A nice overview of the search terms possible is located [here](https://www.atmail.com/blog/imap-commands/).<sup>[[2]](#references)</sup>
    140 
    141 3. Downloading a message (imap command `SELECT Drafts` and then `FETCH 1 BODY[]`)
    142 
    143 ```bash
    144 curl -k 'imaps://1.2.3.4/Drafts;MAILINDEX=1' --user user:pass
    145 ```
    146 
    147 The mail index will be the same index returned from the search operation.
    148 
    149 It is also possible to use a `UID` (unique identifier) to access messages. This is less convenient here because the search command must be formatted manually. For example:
    150 
    151 ```bash
    152 curl -k 'imaps://1.2.3.4/INBOX' -X 'UID SEARCH ALL' --user user:pass
    153 curl -k 'imaps://1.2.3.4/INBOX;UID=1' --user user:pass
    154 ```
    155 
    156 Also, possible to download just parts of a message, e.g. subject and sender of first 5 messages (the `-v` is required to see the subject and sender):
    157 
    158 ```bash
    159 $ curl -k 'imaps://1.2.3.4/INBOX' -X 'FETCH 1:5 BODY[HEADER.FIELDS (SUBJECT FROM)]' --user user:pass -v 2>&1 | grep '^<'
    160 ```
    161 
    162 Although, its probably cleaner to just write a little for loop:
    163 
    164 ```bash
    165 for m in {1..5}; do
    166   echo $m
    167   curl "imap://1.2.3.4/INBOX;MAILINDEX=$m;SECTION=HEADER.FIELDS%20(SUBJECT%20FROM)" --user user:pass
    168 done
    169 ```
    170 
    171 ## Shodan
    172 
    173 - `port:143 CAPABILITY`
    174 - `port:993 CAPABILITY`
    175 
    176 ## HackTricks Automatic Commands
    177 
    178 ```text
    179 Protocol_Name: IMAP    #Protocol Abbreviation if there is one.
    180 Port_Number:  143,993     #Comma separated if there is more than one.
    181 Protocol_Description: Internet Message Access Protocol         #Protocol Abbreviation Spelled out
    182 
    183 Entry_1:
    184   Name: Notes
    185   Description: Notes for IMAP
    186   Note: |
    187     The Internet Message Access Protocol (IMAP) is designed for the purpose of enabling users to access their email messages from any location, primarily through an Internet connection. In essence, emails are retained on a server rather than being downloaded and stored on an individual's personal device. This means that when an email is accessed or read, it is done directly from the server. This capability allows for the convenience of checking emails from multiple devices, ensuring that no messages are missed regardless of the device used.
    188 
    189     https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-imap.html
    190 
    191 Entry_2:
    192   Name: Banner Grab
    193   Description: Banner Grab 143
    194   Command: nc -nv {IP} 143
    195 
    196 Entry_3:
    197   Name: Secure Banner Grab
    198   Description: Banner Grab 993
    199   Command: openssl s_client -connect {IP}:993 -quiet
    200 
    201 Entry_4:
    202   Name: Console-less Metasploit enumeration
    203   Description: IMAP enumeration without the need to run msfconsole
    204   Note: sourced from https://github.com/carlospolop/legion
    205   Command: msfconsole -q -x 'use auxiliary/scanner/imap/imap_version; set RHOSTS {IP}; set RPORT 143; run; exit'
    206 ```
    207 
    208 ## References
    209 
    210 - [1] [IMAP crib sheet - command examples](https://donsutherland.org/crib/imap)
    211 - [2] [Atmail - IMAP Commands overview](https://www.atmail.com/blog/imap-commands/)
    212 - [3] [RFC 9051 - Internet Message Access Protocol (IMAP) Version 4rev2](https://www.rfc-editor.org/rfc/rfc9051)
    213 - [4] [RFC 8314 - Cleartext Considered Obsolete: Use of TLS for Email Submission and Access](https://www.rfc-editor.org/rfc/rfc8314)
    214 - [5] [Nmap NSE documentation - `imap-ntlm-info`](https://nmap.org/nsedoc/scripts/imap-ntlm-info.html)
    215 - [6] [curl documentation - IMAP URL syntax and TLS options](https://curl.se/docs/url-syntax.html#imap)
    216 - [7] [curl source - IMAP protocol implementation](https://github.com/curl/curl/blob/master/lib/imap.c)