How to find Exim mail servers on your network

(updated ), by Thao Doan
icon
Rumble, Inc. is now runZero!

Rumble Network Discovery is now runZero!

In their security advisory for 21Nails, the Qualys Research team communicated their discovery of several critical vulnerabilities in Exim mail servers that can be exploited for unauthenticated code execution and root privileges.

Recently, maintainers of the Exim mail server released updates to patch the vulnerabilities. If you have Exim mail servers, you must patch them immediately.

Finding Exim mail servers with Rumble

According to the Qualys blog, a Shodan search showed nearly 4 million Exim servers exposed to the internet. Their accessibility makes these mail transfer agents targets for attackers.

With Rumble, you can find Exim mail servers in your inventory with this pre-built query. This query searches for any live asset that has protocol SMTP and exim in the banner.

_asset.protocol:smtp and protocol:smtp and banner:exim

As always, any prebuilt queries we create are available from our Queries Library. Check out the library for other useful inventory queries.

Find prebuilt queries in the Queries Library

Try Rumble

Don’t have Rumble and need help finding Ubiquiti devices? Start your Rumble trial today.

Similar Content

September 30, 2022

Finding Microsoft Exchange Servers on your network

GTSC, a Vietnamese security firm, recently discovered two zero-day vulnerabilities that affect Microsoft Exchange Server 2013, 2016, and 2019. These two vulnerabilities are being tracked as CVE-2022-41040 and CVE-2022-41082.

August 4, 2022

Finding DrayTek Vigor routers

The Trellix Threat Labs Vulnerability Research team recently published vulnerability details affecting almost 30 models of DrayTek Vigor routers. This vulnerability resides in the management interface login page and is trivial to exploit via buffer overflow. An …

Read More

July 29, 2022

Hunting for X.509 Certificates

X.509 certificates are used to secure communications over both trusted and untrusted networks. Protocols such as Transport Layer Security (TLS) rely on X.509 certificates to keep their communications secure between endpoints. Each X.509 certificate is composed of a public …

Read More