
ruler
A tool to abuse Exchange services

A tool to abuse Exchange services

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Proof of Concept for CVE-2023-23397 in Python

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

对Exchange Proxyshell 做了二次修改,精确的拆分、实现辅助性安全测试。

Python script for sending e-mails with CVE-2023-23397 payload using SMTP



Python script to create a message with the vulenrability properties set

CVE-2023-23397漏洞的简单PoC,有效载荷通过电子邮件发送。

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.

Cisco Email Security Appliance: Email to zero-click RCE as root - Remote Code Execution/Memory Corruption/ROP-chain