> For the complete documentation index, see [llms.txt](https://strange-1.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://strange-1.gitbook.io/notes/enumeration/imap-pop3-110-143-993-995.md).

# IMAP, POP3 - 110,143,993,995

#### IMAP Commands

| Command                       | Description                                                                                               |
| ----------------------------- | --------------------------------------------------------------------------------------------------------- |
| 1 LOGIN username password     | User's login.                                                                                             |
| 1 LIST "" \*                  | Lists all directories.                                                                                    |
| 1 CREATE "INBOX"              | Creates a mailbox with a specified name.                                                                  |
| 1 DELETE "INBOX"              | Deletes a mailbox.                                                                                        |
| 1 RENAME "ToRead" "Important" | Renames a mailbox.                                                                                        |
| 1 LSUB "" \*                  | Returns a subset of names from the set of names that the User has declared as being active or subscribed. |
| 1 SELECT INBOX                | Selects a mailbox so that messages in the mailbox can be accessed.                                        |
| 1 UNSELECT INBOX              | Exits the selected mailbox.                                                                               |
| 1 FETCH \<ID> all             | Retrieves data associated with a message in the mailbox.                                                  |
| 1 CLOSE                       | Removes all messages with the Deleted flag set.                                                           |
| 1 LOGOUT                      | Closes the connection with the IMAP server.                                                               |

#### POP3 Commands

| Command       | Description                                                 |
| ------------- | ----------------------------------------------------------- |
| USER username | Identifies the user.                                        |
| PASS password | Authentication of the user using its password.              |
| STAT          | Requests the number of saved emails from the server.        |
| LIST          | Requests from the server the number and size of all emails. |
| RETR id       | Requests the server to deliver the requested email by ID.   |
| DELE id       | Requests the server to delete the requested email by ID.    |
| CAPA          | Requests the server to display the server capabilities.     |
| RSET          | Requests the server to reset the transmitted information.   |
| QUIT          | Closes the connection with the POP3 server.                 |

### Interacting with service

```bash
# POP3
telnet ip 110

# login using username and password
USER admin
PASS password

# list all mails of user
LIST 

# read mails using id no.   
RETR 1
```

### Nmap

```bash
# nmap scan  
nmap ip -sV -p110,143,993,995 -sC
```

### cURL

```bash
# footprinting using curl with valid user and pass 
curl -k 'imaps://ip' --user user:p4ssw0rd

curl -k 'imaps://ip' --user user:1234 -v
```

### **OpenSSL - TLS Encrypted Interaction POP3**

```bash
# OpenSSL - TLS Encrypted Interaction POP3
openssl s_client -connect ip:pop3s

# OpenSSL - TLS Encrypted Interaction IMAP
openssl s_client -connect ip:imaps
```
