Skip to content

Commit a5cc4e7

Browse files
authored
Merge pull request #2984 from HackTricks-wiki/research_update_src_network-services-pentesting_pentesting-smtp_README_20260929_234415
Research Update Enhanced src/network-services-pentesting/pen...
2 parents d1fff27 + 51af735 commit a5cc4e7

1 file changed

Lines changed: 35 additions & 2 deletions

File tree

  • src/network-services-pentesting/pentesting-smtp

‎src/network-services-pentesting/pentesting-smtp/README.md‎

Lines changed: 35 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -564,6 +564,37 @@ For checking whether a mail server is an open relay (which means it could forwar
564564
nmap -p25 --script smtp-open-relay 10.10.10.10 -v
565565
```
566566
567+
#### PROXY protocol source-address spoofing
568+
569+
A load balancer can prepend a **PROXY protocol** header so the SMTP backend sees the original client's IP address. A PROXY-enabled SMTP listener waits for this header **before** sending its `220` banner. If the backend is reachable directly and trusts headers from arbitrary peers, an attacker can claim to be `127.0.0.1` or an internal address. The forged address may match `mynetworks` or another IP allowlist and turn the server into an open relay. A 2025 measurement study confirmed this behavior on 373 SMTP servers.<sup>[[14]](#references)[[15]](#references)</sup>
570+
571+
First compare a normal connection with a valid PROXY v1 preamble. The fields are protocol, claimed source IP, destination IP, source port, and destination port. The line must end in CRLF and must be the first bytes sent on the TCP connection.<sup>[[14]](#references)</sup>
572+
573+
```bash
574+
TARGET_IP=203.0.113.25
575+
nc -nv -w 3 "$TARGET_IP" 25
576+
printf 'PROXY TCP4 198.51.100.23 %s 40000 25\r\nQUIT\r\n' "$TARGET_IP" | nc -nv -w 3 "$TARGET_IP" 25
577+
```
578+
579+
A banner that appears only after the preamble is a strong PROXY-protocol signal. A listener that answers both probes may also support it, so compare its banner and logged peer address.<sup>[[14]](#references)</sup>
580+
581+
During an authorized relay test, use `ncat --crlf` and send the PROXY line **before waiting for the banner**. Use only a recipient address you control. Stop with `RSET` before message data if delivery is unnecessary.<sup>[[14]](#references)</sup>
582+
583+
```text
584+
$ ncat --crlf -nv 203.0.113.25 25
585+
PROXY TCP4 127.0.0.1 203.0.113.25 40000 25
586+
220 mail.example ESMTP
587+
EHLO audit.example
588+
MAIL FROM:<probe@audit.example>
589+
RCPT TO:<owned-address@external.example>
590+
RSET
591+
QUIT
592+
```
593+
594+
Repeat the same envelope from an ordinary SMTP connection. If the external `RCPT TO` is accepted only when the claimed source is loopback or RFC1918 space, the server is using attacker-controlled PROXY metadata for relay authorization. Also test each exposed SMTP endpoint because the public proxy and the backend listener can enforce different rules.<sup>[[14]](#references)</sup>
595+
596+
The reliable fix is to make the PROXY listener reachable only from the real load balancer. Firewall the backend to the exact proxy addresses and never share the same listener between direct SMTP clients and PROXY-protocol clients. Relay policy should not depend only on a client IP supplied by this header.<sup>[[14]](#references)[[15]](#references)</sup>
597+
567598
### **Tools**
568599
569600
- [**https://github.com/serain/mailspoof**](https://github.com/serain/mailspoof) **Check for SPF and DMARC misconfigurations**
@@ -765,6 +796,8 @@ Entry_8:
765796
766797
```
767798
799+
800+
768801
## References
769802
770803
- [1] [XBOW – Dead.Letter (CVE-2026-45185): How XBOW Found an Unauthenticated RCE on Exim](https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim)
@@ -780,6 +813,6 @@ Entry_8:
780813
- [11] [RFC 7208 – Sender Policy Framework (SPF)](https://www.rfc-editor.org/rfc/rfc7208)
781814
- [12] [RFC 6376 – DomainKeys Identified Mail (DKIM) Signatures](https://www.rfc-editor.org/rfc/rfc6376)
782815
- [13] [RFC 7489 – Domain-based Message Authentication, Reporting, and Conformance (DMARC)](https://www.rfc-editor.org/rfc/rfc7489)
783-
784-
816+
- [14] [A Large-Scale Measurement Study of the PROXY Protocol and its Security Implications](https://seclab.cs.ucsb.edu/files/publications/pletinckx2025proxy.pdf)
817+
- [15] [APNIC Blog – A first look at the PROXY protocol and its security implications](https://blog.apnic.net/2025/07/01/a-first-look-at-the-proxy-protocol-and-its-security-implications/)
785818
{{#include ../../banners/hacktricks-training.md}}

0 commit comments

Comments
 (0)