
CVE-2026-24031
Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Identify public-facing Microsoft Exchange servers and determine their software versions

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

Educational lab demonstrating CVE-2024-21413 Outlook vulnerability exploitation with Python email exploit tool and Responder for NTLM credential…

Python tool to exploit CVE-2021-26855 (ProxyLogon) for downloading Exchange mailbox emails via EWS, supporting user enumeration and bulk target…

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

A tool to abuse Exchange services

ntlm relay attack to Exchange Web Services

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

small python3 tool to check common vulnerabilities in SMTP servers

Tool to find SMTP servers vulnerable to open relay

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

A simple Reverse Shell that can communicate through Gmail SMTP or any other SMTP to evade network restrictions

Spam Scanner is a Node.js anti-spam, email filtering, and phishing prevention tool and service. Built for @ladjs, @forwardemail, @cabinjs, @breejs,…

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.