daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-pop.md (5163B)


      1 ---
      2 title: "110,995 - Pentesting POP"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-pop.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-pop.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 110,995 - Pentesting POP
     14 
     15 ## Basic Information
     16 
     17 POP3 lets a client authenticate to a maildrop, list and retrieve messages, optionally mark messages for deletion, and commit those deletions on a successful `QUIT`. Downloading does not inherently delete every message; client settings determine whether `DELE` is issued.<sup>[[2]](#references)</sup>
     18 
     19 **Common ports:** 110 for POP3 (optionally upgraded with STLS) and 995 for implicit TLS.<sup>[[2]](#references)[[3]](#references)</sup>
     20 
     21 ```text
     22 PORT    STATE SERVICE
     23 110/tcp open  pop3
     24 ```
     25 
     26 ## Enumeration
     27 
     28 ### Banner Grabbing
     29 
     30 ```bash
     31 nc -nv <IP> 110
     32 openssl s_client -connect <IP>:995 -crlf -quiet
     33 ```
     34 
     35 ## Manual
     36 
     37 You can use the command `CAPA` to obtain the capabilities of the POP3 server.
     38 
     39 ## Automated
     40 
     41 ```bash
     42 nmap --script "pop3-capabilities or pop3-ntlm-info" -sV -p <PORT> <IP> # Both are default scripts
     43 ```
     44 
     45 The `pop3-ntlm-info` plugin will return some "**sensitive**" data (Windows versions).
     46 
     47 ### [POP3 bruteforce](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#pop)
     48 
     49 ## POP syntax
     50 
     51 POP commands examples from [here](http://sunnyoasis.com/services/emailviatelnet.html)<sup>[[1]](#references)</sup>
     52 
     53 ```bash
     54 POP commands:
     55   USER uid           Log in as "uid"
     56   PASS password      Substitute "password" with your actual password
     57   STAT               List number of messages, total mailbox size
     58   LIST               List messages and sizes
     59   RETR n             Show message n
     60   DELE n             Mark message n for deletion
     61   RSET               Undo any changes
     62   QUIT               Logout (expunges messages if no RSET)
     63   TOP msg n          Show first n lines of message number msg
     64   CAPA               Get capabilities
     65 ```
     66 
     67 Example:
     68 
     69 ```text
     70 root@kali:~# telnet $ip 110
     71  +OK beta POP3 server (JAMES POP3 Server 2.3.2) ready
     72  USER billydean
     73  +OK
     74  PASS password
     75  +OK Welcome billydean
     76 
     77  list
     78 
     79  +OK 2 1807
     80  1 786
     81  2 1021
     82 
     83  retr 1
     84 
     85  +OK Message follows
     86  From: jamesbrown@motown.com
     87  Dear Billy Dean,
     88 
     89  Here is your login for remote desktop ... try not to forget it this time!
     90  username: billydean
     91  password: PA$$W0RD!Z
     92 ```
     93 
     94 ## Logging Passwords
     95 
     96 POP servers with the setting **`auth_debug`** enabled will be increasing the logs generated. However, if **`auth_debug_passwords`** or **`auth_verbose_passwords`** are set as **`true`**, password could be also logged in clear text in those logs.
     97 
     98 ## HackTricks Automatic Commands
     99 
    100 ```text
    101 Protocol_Name:  POP   #Protocol Abbreviation if there is one.
    102 Port_Number:  110     #Comma separated if there is more than one.
    103 Protocol_Description: Post Office Protocol         #Protocol Abbreviation Spelled out
    104 
    105 Entry_1:
    106   Name: Notes
    107   Description: Notes for POP
    108   Note: |
    109     Post Office Protocol (POP) is described as a protocol within the realm of computer networking and the Internet, which is utilized for the extraction and retrieval of email from a remote mail server**, making it accessible on the local device. Positioned within the application layer of the OSI model, this protocol enables users to fetch and receive email. The operation of POP clients typically involves establishing a connection to the mail server, downloading all messages, storing these messages locally on the client system, and subsequently removing them from the server. Although there are three iterations of this protocol, POP3 stands out as the most prevalently employed version.
    110 
    111     https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-pop.html
    112 
    113 Entry_2:
    114   Name: Banner Grab
    115   Description: Banner Grab 110
    116   Command: nc -nv {IP} 110
    117 
    118 Entry_3:
    119   Name: Banner Grab 995
    120   Description: Grab Banner Secure
    121   Command: openssl s_client -connect {IP}:995 -crlf -quiet
    122 
    123 Entry_4:
    124   Name: Nmap
    125   Description: Scan for POP info
    126   Command: nmap --script "pop3-capabilities or pop3-ntlm-info" -sV -p 110 {IP}
    127 
    128 Entry_5:
    129   Name: Hydra Brute Force
    130   Description: Need User
    131   Command: hydra -l {Username} -P {Big_Passwordlist} -f {IP} pop3 -V
    132 
    133 Entry_6:
    134   Name: consolesless mfs enumeration
    135   Description: POP3 enumeration without the need to run msfconsole
    136   Note: this NSE workflow is also used by Legion.<sup>[[4]](#references)</sup>
    137   Command: msfconsole -q -x 'use auxiliary/scanner/pop3/pop3_version; set RHOSTS {IP}; set RPORT 110; run; exit'
    138 
    139 ```
    140 
    141 ## References
    142 
    143 - [1] [Sending and Receiving Email via Telnet](http://sunnyoasis.com/services/emailviatelnet.html)
    144 - [2] [RFC 1939 — Post Office Protocol Version 3](https://www.rfc-editor.org/rfc/rfc1939.html)
    145 - [3] [RFC 8314 — Cleartext considered obsolete; implicit TLS for email access](https://www.rfc-editor.org/rfc/rfc8314.html)
    146 - [4] [carlospolop/legion](https://github.com/carlospolop/legion)