pentesting-pop.md (5163B)
1 --- 2 title: "110,995 - Pentesting POP" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-pop.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-pop.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 110,995 - Pentesting POP 14 15 ## Basic Information 16 17 POP3 lets a client authenticate to a maildrop, list and retrieve messages, optionally mark messages for deletion, and commit those deletions on a successful `QUIT`. Downloading does not inherently delete every message; client settings determine whether `DELE` is issued.<sup>[[2]](#references)</sup> 18 19 **Common ports:** 110 for POP3 (optionally upgraded with STLS) and 995 for implicit TLS.<sup>[[2]](#references)[[3]](#references)</sup> 20 21 ```text 22 PORT STATE SERVICE 23 110/tcp open pop3 24 ``` 25 26 ## Enumeration 27 28 ### Banner Grabbing 29 30 ```bash 31 nc -nv <IP> 110 32 openssl s_client -connect <IP>:995 -crlf -quiet 33 ``` 34 35 ## Manual 36 37 You can use the command `CAPA` to obtain the capabilities of the POP3 server. 38 39 ## Automated 40 41 ```bash 42 nmap --script "pop3-capabilities or pop3-ntlm-info" -sV -p <PORT> <IP> # Both are default scripts 43 ``` 44 45 The `pop3-ntlm-info` plugin will return some "**sensitive**" data (Windows versions). 46 47 ### [POP3 bruteforce](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#pop) 48 49 ## POP syntax 50 51 POP commands examples from [here](http://sunnyoasis.com/services/emailviatelnet.html)<sup>[[1]](#references)</sup> 52 53 ```bash 54 POP commands: 55 USER uid Log in as "uid" 56 PASS password Substitute "password" with your actual password 57 STAT List number of messages, total mailbox size 58 LIST List messages and sizes 59 RETR n Show message n 60 DELE n Mark message n for deletion 61 RSET Undo any changes 62 QUIT Logout (expunges messages if no RSET) 63 TOP msg n Show first n lines of message number msg 64 CAPA Get capabilities 65 ``` 66 67 Example: 68 69 ```text 70 root@kali:~# telnet $ip 110 71 +OK beta POP3 server (JAMES POP3 Server 2.3.2) ready 72 USER billydean 73 +OK 74 PASS password 75 +OK Welcome billydean 76 77 list 78 79 +OK 2 1807 80 1 786 81 2 1021 82 83 retr 1 84 85 +OK Message follows 86 From: jamesbrown@motown.com 87 Dear Billy Dean, 88 89 Here is your login for remote desktop ... try not to forget it this time! 90 username: billydean 91 password: PA$$W0RD!Z 92 ``` 93 94 ## Logging Passwords 95 96 POP servers with the setting **`auth_debug`** enabled will be increasing the logs generated. However, if **`auth_debug_passwords`** or **`auth_verbose_passwords`** are set as **`true`**, password could be also logged in clear text in those logs. 97 98 ## HackTricks Automatic Commands 99 100 ```text 101 Protocol_Name: POP #Protocol Abbreviation if there is one. 102 Port_Number: 110 #Comma separated if there is more than one. 103 Protocol_Description: Post Office Protocol #Protocol Abbreviation Spelled out 104 105 Entry_1: 106 Name: Notes 107 Description: Notes for POP 108 Note: | 109 Post Office Protocol (POP) is described as a protocol within the realm of computer networking and the Internet, which is utilized for the extraction and retrieval of email from a remote mail server**, making it accessible on the local device. Positioned within the application layer of the OSI model, this protocol enables users to fetch and receive email. The operation of POP clients typically involves establishing a connection to the mail server, downloading all messages, storing these messages locally on the client system, and subsequently removing them from the server. Although there are three iterations of this protocol, POP3 stands out as the most prevalently employed version. 110 111 https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-pop.html 112 113 Entry_2: 114 Name: Banner Grab 115 Description: Banner Grab 110 116 Command: nc -nv {IP} 110 117 118 Entry_3: 119 Name: Banner Grab 995 120 Description: Grab Banner Secure 121 Command: openssl s_client -connect {IP}:995 -crlf -quiet 122 123 Entry_4: 124 Name: Nmap 125 Description: Scan for POP info 126 Command: nmap --script "pop3-capabilities or pop3-ntlm-info" -sV -p 110 {IP} 127 128 Entry_5: 129 Name: Hydra Brute Force 130 Description: Need User 131 Command: hydra -l {Username} -P {Big_Passwordlist} -f {IP} pop3 -V 132 133 Entry_6: 134 Name: consolesless mfs enumeration 135 Description: POP3 enumeration without the need to run msfconsole 136 Note: this NSE workflow is also used by Legion.<sup>[[4]](#references)</sup> 137 Command: msfconsole -q -x 'use auxiliary/scanner/pop3/pop3_version; set RHOSTS {IP}; set RPORT 110; run; exit' 138 139 ``` 140 141 ## References 142 143 - [1] [Sending and Receiving Email via Telnet](http://sunnyoasis.com/services/emailviatelnet.html) 144 - [2] [RFC 1939 — Post Office Protocol Version 3](https://www.rfc-editor.org/rfc/rfc1939.html) 145 - [3] [RFC 8314 — Cleartext considered obsolete; implicit TLS for email access](https://www.rfc-editor.org/rfc/rfc8314.html) 146 - [4] [carlospolop/legion](https://github.com/carlospolop/legion)