You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit a5cc4e7
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: src/network-services-pentesting/pentesting-smtp/README.md
+35-2Lines changed: 35 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -564,6 +564,37 @@ For checking whether a mail server is an open relay (which means it could forwar
564
564
nmap -p25 --script smtp-open-relay 10.10.10.10 -v
565
565
```
566
566
567
+
#### PROXY protocol source-address spoofing
568
+
569
+
A load balancer can prepend a **PROXY protocol** header so the SMTP backend sees the original client's IP address. A PROXY-enabled SMTP listener waits for this header **before** sending its `220` banner. If the backend is reachable directly and trusts headers from arbitrary peers, an attacker can claim to be `127.0.0.1` or an internal address. The forged address may match `mynetworks` or another IP allowlist and turn the server into an open relay. A 2025 measurement study confirmed this behavior on 373 SMTP servers.<sup>[[14]](#references)[[15]](#references)</sup>
570
+
571
+
First compare a normal connection with a valid PROXY v1 preamble. The fields are protocol, claimed source IP, destination IP, source port, and destination port. The line must end in CRLF and must be the first bytes sent on the TCP connection.<sup>[[14]](#references)</sup>
A banner that appears only after the preamble is a strong PROXY-protocol signal. A listener that answers both probes may also support it, so compare its banner and logged peer address.<sup>[[14]](#references)</sup>
580
+
581
+
During an authorized relay test, use `ncat --crlf` and send the PROXY line **before waiting for the banner**. Use only a recipient address you control. Stop with `RSET` before message data if delivery is unnecessary.<sup>[[14]](#references)</sup>
582
+
583
+
```text
584
+
$ ncat --crlf -nv 203.0.113.25 25
585
+
PROXY TCP4 127.0.0.1 203.0.113.25 40000 25
586
+
220 mail.example ESMTP
587
+
EHLO audit.example
588
+
MAIL FROM:<probe@audit.example>
589
+
RCPT TO:<owned-address@external.example>
590
+
RSET
591
+
QUIT
592
+
```
593
+
594
+
Repeat the same envelope from an ordinary SMTP connection. If the external `RCPT TO` is accepted only when the claimed source is loopback or RFC1918 space, the server is using attacker-controlled PROXY metadata for relay authorization. Also test each exposed SMTP endpoint because the public proxy and the backend listener can enforce different rules.<sup>[[14]](#references)</sup>
595
+
596
+
The reliable fix is to make the PROXY listener reachable only from the real load balancer. Firewall the backend to the exact proxy addresses and never share the same listener between direct SMTP clients and PROXY-protocol clients. Relay policy should not depend only on a client IP supplied by this header.<sup>[[14]](#references)[[15]](#references)</sup>
597
+
567
598
### **Tools**
568
599
569
600
- [**https://github.com/serain/mailspoof**](https://github.com/serain/mailspoof) **Check for SPF and DMARC misconfigurations**
@@ -765,6 +796,8 @@ Entry_8:
765
796
766
797
```
767
798
799
+
800
+
768
801
## References
769
802
770
803
- [1] [XBOW – Dead.Letter (CVE-2026-45185): How XBOW Found an Unauthenticated RCE on Exim](https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim)
- [14] [A Large-Scale Measurement Study of the PROXY Protocol and its Security Implications](https://seclab.cs.ucsb.edu/files/publications/pletinckx2025proxy.pdf)
817
+
- [15] [APNIC Blog – A first look at the PROXY protocol and its security implications](https://blog.apnic.net/2025/07/01/a-first-look-at-the-proxy-protocol-and-its-security-implications/)
0 commit comments