
RedTeamScripts
Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Python exploit for Roundcube Webmail DOM-based XSS (CVE-2026-25916) via SVG href attributes, enabling session hijacking and data exfiltration through…

Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.


Um estudo de caso do CVE-2024-21413. Usado como parâmetro a sala do TryHackMe Moniker Link (CVE-2024-21413). Feito edições com claude code no exploit.

CVE-2023-23397漏洞的简单PoC,有效载荷通过电子邮件发送。

Python exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Sends a crafted email via SMTP to trigger code execution…

Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.

Proof of Concept for CVE-2023-23397 in Python

Cisco Email Security Appliance: Email to zero-click RCE as root - Remote Code Execution/Memory Corruption/ROP-chain

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

对Exchange Proxyshell 做了二次修改,精确的拆分、实现辅助性安全测试。

C# PoC exploit for CVE-2023-23397 that sends malicious Outlook meeting invites with a UNC path trigger for NTLM credential theft.

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC