
CVE-2026-24031
Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

🦄 A curated list of privacy & security-focused software and services

Dockerized mail server suite with Postfix, Dovecot, Rspamd, and ClamAV. Provides secure email hosting with integrated spam filtering, antivirus, and…

Self-hosted email alias masking service using Postfix and Telegram bot to create disposable addresses for signups, with full control over email…

Detailed CVE-2026-51788 advisory for a DoS vulnerability in cleverange_auth v0.1.10, with technical analysis, CVSS scoring, and mitigation guidance…

Modular Java mail server supporting IMAP, SMTP, POP3, and JMAP with Docker deployment, distributed architecture, and CLI management for secure…

A Python package and CLI for parsing aggregate and forensic DMARC reports

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

Fork of laravel/framework 10.50.2 with CVE-2026-48019 (CRLF injection in default email rule) backported into ValidatesAttributes::validateEmail.…

Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.