ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 59 - PT0-002 discussion

Report
Export

A mail service company has hired a penetration tester to conduct an enumeration of all user accounts on an SMTP server to identify whether previous staff member accounts are still active.

Which of the following commands should be used to accomplish the goal?

A.
VRFY and EXPN
Answers
A.
VRFY and EXPN
B.
VRFY and TURN
Answers
B.
VRFY and TURN
C.
EXPN and TURN
Answers
C.
EXPN and TURN
D.
RCPT TO and VRFY
Answers
D.
RCPT TO and VRFY
Suggested answer: A

Explanation:

The VRFY and EXPN commands can be used to enumerate user accounts on an SMTP server, as they are used to verify the existence of users or mailing lists. VRFY (verify) asks the server to confirm that a given user name or address is valid. EXPN (expand) asks the server to expand a mailing list into its individual members. These commands can be used by a penetration tester to identify valid user names or e-mail addresses on the target SMTP server.

Reference: https://hackerone.com/reports/193314

asked 02/10/2024
piera d'addelfio
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first