Mail Server Attacks Cheat Sheet
Mail Server Attacks Cheat Sheet
IMAP
Information Gathering
Attacks
NTLM Auth
Bruteforce
POP3
Information Gathering
Attacks
NTLM Auth
Bruteforce
SMTP
Information Gathering
Attacks
NTLM Auth
Bruteforce
Spoofing
Non Auth
Zimbra
https://md2pdf.netlify.app 1/10
4/30/24, 8:06 AM Mail Server Attacks Cheat Sheet
Information Gathering
Attacks
Misconfiguration
Anti-Malware
ActiveSync(LDAP)
ActiveSync(SMB Share)
Phishing
Known Vuln
Spray
Roundcube
Information Gathering
Attacks
Anti-Malware
ActiveSync(LDAP)
ActiveSync(SMB Share)
Phishing
Known Vuln
Spray
Microsoft Exchange
Information Gathering
Attacks
AutotDiscover
Known Vuln
Spray
NTLM Auth
NTLMRelay
GAL
Exchange Admin Group Deligation
Rule
Forms
Anti-Malware
ActiveSync(LDAP)
ActiveSync(SMB Share)
ActiveSync(WSS)
RPC
LDAP
Phishing
https://md2pdf.netlify.app 2/10
4/30/24, 8:06 AM Mail Server Attacks Cheat Sheet
IMAP
Information Gathering
Attacks
NTLM Auth
a1 AUTHENTICATE NTLM
Bruteforce
POP3
Information Gathering
https://md2pdf.netlify.app 3/10
4/30/24, 8:06 AM Mail Server Attacks Cheat Sheet
Attacks
NTLM Auth
a1 AUTHENTICATE NTLM
Bruteforce
SMTP
Information Gathering
nmap [-sS] [-sC] -Pn -p 25,465,587 -sV --script=banner or --script smtp-commands [IP]
Attacks
NTLM Auth
https://md2pdf.netlify.app 4/10
4/30/24, 8:06 AM Mail Server Attacks Cheat Sheet
a1 AUTHENTICATE NTLM
Bruteforce
Spoofing
emkei.cz
Non Auth
Zimbra
Information Gathering
Attacks
Misconfiguration
https://md2pdf.netlify.app 5/10
4/30/24, 8:06 AM Mail Server Attacks Cheat Sheet
modules/auxiliary/gather/memcached_extractor
Anti-Malware
evilmacro
macropack
...
ActiveSync(LDAP)
ActiveSync(SMB Share)
Phishing
gophish
Known Vuln
CVE‑2022‑37042
CVE‑2022‑37041
CVE‑2022‑37044
Spray
POST
Roundcube
Information Gathering
https://md2pdf.netlify.app 6/10
4/30/24, 8:06 AM Mail Server Attacks Cheat Sheet
Attacks
Anti-Malware
evilmacro
macropack
...
ActiveSync(LDAP)
ActiveSync(SMB Share)
Phishing
gophish
Known Vuln
2021-44026
Spray
POST
Microsoft Exchange
Information Gathering
https://md2pdf.netlify.app 7/10
4/30/24, 8:06 AM Mail Server Attacks Cheat Sheet
Attacks
AutotDiscover
autodiscover/autodiscover.xml
Known Vuln
ProxyLogon(2021-26855)
ProxyShell(2021-34473)
HAFNIUM(2021-26858)
Spray
Invoke-PasswordSprayOWA
Invoke-PasswordSprayEWS
NTLM Auth
NTLMRelay
reponder
./exchangeRelayx.py -t https://mail.xyzczz.com
GAL
Bloodhound
net
Rule
https://md2pdf.netlify.app 8/10
4/30/24, 8:06 AM Mail Server Attacks Cheat Sheet
GUI
Ruler
Forms
./ruler --email [email protected] form add --suffix superduper --input command.txt --send
Anti-Malware
evilmacro
macropack
...
ActiveSync(LDAP)
ActiveSync(SMB Share)
ActiveSync(WSS)
RPC
https://md2pdf.netlify.app 9/10
4/30/24, 8:06 AM Mail Server Attacks Cheat Sheet
LDAP
Phishing
gophish
https://md2pdf.netlify.app 10/10