06 March 2009 | 4,443 views

fzem – MUA (Mail User Agent) / Mail Client Fuzzer

Check For Vulnerabilities with Acunetix

fzem is a MUA (mail user agent) fuzzer that fuzzes MAIL/MIME email headers as well as how clients handle SMTP, POP and IMAP responses.

Purpose

fzem’s purpose is to fuzz MUAs as they process email content and handle server reponses.

How does it work?

fzem has the three main mail protocols implemented as well as mail/mime headers. Using these we can manipulate emails and responses to include fuzzing data from our fuzzing oracle or from the user.

A user can command fzem to run in various modes and perform differently in those modes.

  • Fuzz SMTP OK responses
  • Fuzz SMTP ERROR responses
  • Fuzz SMTP using custom fuzz data
  • Fuzz MAIL/MIME headers
  • Fuzz MAIL/MIME headers using custom fuzz data
  • Fuzz MAIL/MIME headers using custom headers
  • Fuzz POP3 OK responses
  • Fuzz POP3 ERROR responses
  • Fuzz POP3 using custom fuzz data
  • Fuzz IMAP4 OK responses
  • Fuzz IMAP4 ERROR responses
  • Fuzz IMAP4 using custom fuzz data

We can also choose a specific port to listen on (-P) and take advantage of the useful debug option (-D).

You can download fzem here:

fzem.tar.gz

Or read more here.

Advertisements



Recent in Exploits/Vulnerabilities:
- Apple’s Password Storing Keychain Cracked on iOS & OS X
- The Logjam Attack – ANOTHER Critical TLS Weakness
- WordPress Critical Zero-Day Vulnerability Fixed In A Hurry

Related Posts:
- Fake Microsoft Patch – BeastPWS-C
- Taof 0.1 Network Protocol Fuzzer Released
- Browser Fuzzer 3 (bf3) – Comprehensive Web Browser Fuzzing Tool

Most Read in Exploits/Vulnerabilities:
- Learn to use Metasploit – Tutorials, Docs & Videos - 230,700 views
- AJAX: Is your application secure enough? - 119,546 views
- eEye Launches 0-Day Exploit Tracker - 85,233 views

Advertise on Darknet

One Response to “fzem – MUA (Mail User Agent) / Mail Client Fuzzer”

  1. navin 7 March 2009 at 10:59 am Permalink

    wow, and I thought this couldn’t be done!! Thanks krakowlabs!!