Solved

Question of the day 10/09, Cybersecurity Edition

  • 12 September 2022
  • 7 comments
  • 41 views

Userlevel 7
Badge +13

Day 9

What is the command that enumerate email addresses present on a SMTP server?

  • HASH
  • VRFY
  • READ
  • EXPN
  • RCPT TO
icon

Best answer by marcofabbri 13 September 2022, 07:54

View original

7 comments

Userlevel 7
Badge +7

VERIFY or should that be VRFY 😉

Userlevel 7
Badge +13

VERIFY or should that be VRFY 😉

Thanks, corrected. Monday morning...

Userlevel 7
Badge +7

I know the feeling. Just need that coffee

Userlevel 7
Badge +20

RCPT TO

Userlevel 7
Badge +17

VRFY

But this command can be a security problem, because you can extract valid email addresses and use them for further attacks against server and try them as login names…. You cannot disable it completely because the RFC requests it. You can configure it that it gives no real information instead….

Userlevel 7
Badge +20

RCPT TO

Correction - should be VRFY 😂

Userlevel 7
Badge +13

This one was tricky. Correct answer was EXPN, VRFY and RCPT TO 😋

All three commands are good to enumeration email addresses on a SMTP server.

Here’s an example:
 

VRFY command, and EXPN is very similar.
RCPT TO command

 

Comment