
ruler
A tool to abuse Exchange services

A tool to abuse Exchange services

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

Proof of Concept for CVE-2023-23397 in Python

对Exchange Proxyshell 做了二次修改,精确的拆分、实现辅助性安全测试。

C# PoC exploit for CVE-2023-23397 that sends malicious Outlook meeting invites with a UNC path trigger for NTLM credential theft.

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…

Python script to create a message with the vulenrability properties set


Python exploit for Roundcube Webmail DOM-based XSS (CVE-2026-25916) via SVG href attributes, enabling session hijacking and data exfiltration through…

CVE-2023-23397漏洞的简单PoC,有效载荷通过电子邮件发送。