
CVE-2020-16947
PoC of CVE-2020-16947 (Microsoft Outlook RCE vulnerablility)

PoC of CVE-2020-16947 (Microsoft Outlook RCE vulnerablility)

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

Automated pipeline that resolves Swiss municipality domains, scrapes websites for email addresses, and classifies email providers via MX, SPF, DKIM,…


Tool to find SMTP servers vulnerable to open relay

amavis is a high-performance email content filter framework written in Perl.

Automated SPF and DMARC configuration checker that identifies email spoofing vulnerabilities across single or bulk domains using DNS lookups.

A simple Python script that reads a text file with lots of e-mails and passwords, and tries to check if those credentials are valid by trying to…


All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.

Artifacts for the USENIX publication.

Web application that lets you test if your domain is vulnerable to email spoofing

A home for detection content developed by the delivr.to team

Zeroday Microsoft Exchange Server checker (Virtual Patching checker)

A program to map out SPF and DKIM records for a large number of domains

mboxShell. Fast terminal viewer for MBOX files of any size. Open, search and export emails from Gmail Takeout backups (50GB+) without loading them…

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC

Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match.