
area51
The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

PoC and technical write-up for CVE-2025-43920, a remote command injection in GNU Mailman 2.1.39's external archiver allowing unauthenticated code…

Exploit for Outlook 2019 zero-click vulnerability CVE-2020-1349, using MIME header parsing bugs to achieve heap overflow and EIP control via vftable…

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…


Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…

Paperweight scans your inbox to map your digital footprint, then helps you take back control and delete your data. Local-first and open source.

A simple Reverse Shell that can communicate through Gmail SMTP or any other SMTP to evade network restrictions

Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

Self-hosted email alias masking service using Postfix and Telegram bot to create disposable addresses for signups, with full control over email…

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs