WMAT Released – Web Mail Auth Tool For Testing Web Mail Logins


WMAT is Web Mail Auth Tool that provide some essential functions for testing web mail logins, written in python with support of pyCurl.

How it works?

It is very simple, You give WMAT file with usernames, file with passwords, URL of web mail app and chose pattern for attack. Patterns are XML files that define post/get fields, http method, referer, success tag, etc … for each web mail applications.

There are currently patterns for horde, squirrelmail, kerio and mdaemon web mail.

The XML pattern files look like this:


The author of WMAT requests for help from the community with the patterns, the author of the pattern will be credited in the author field of the XML file.

There are some more options like setting timeout (time between each request), bell on success and option for writing output in file. More can be seen in the Readme file here.

For future versions the following additions are planned:

  • using a proxy
  • special addon for generation of usernames/passwords
  • automatic recognizer of web app

You can download WMAT here:

wmat.zip
Python source.

Or read more here.

Posted in: Hacking Tools, Password Cracking Tools, Web Hacking


Latest Posts:


GitLab Watchman - Audit Gitlab For Sensitive Data & Credentials GitLab Watchman – Audit Gitlab For Sensitive Data & Credentials
GitLab Watchman is an app that uses the GitLab API to audit GitLab for sensitive data and credentials exposed internally, this includes code, commits, wikis etc
GKE Auditor - Detect Google Kubernetes Engine Misconfigurations GKE Auditor – Detect Google Kubernetes Engine Misconfigurations
GKE Auditor is a Java-based tool to detect Google Kubernetes Engine misconfigurations, it aims to help security & dev teams streamline the configuration process
zANTI - Android Wireless Hacking Tool Free Download zANTI – Android Wireless Hacking Tool Free Download
zANTI is an Android Wireless Hacking Tool that functions as a mobile penetration testing toolkit that lets you assess the risk level of a network using mobile.
HELK - Open Source Threat Hunting Platform HELK – Open Source Threat Hunting Platform
The Hunting ELK or simply the HELK is an Open-Source Threat Hunting Platform with advanced analytics capabilities such as SQL declarative language, graphing etc
trape - OSINT Analysis Tool For People Tracking Trape – OSINT Analysis Tool For People Tracking
Trape is an OSINT analysis tool, which allows people to track and execute intelligent social engineering attacks in real-time.
Fuzzilli - JavaScript Engine Fuzzing Library Fuzzilli – JavaScript Engine Fuzzing Library
Fuzzilii is a JavaScript engine fuzzing library, it's a coverage-guided fuzzer for dynamic language interpreters based on a custom intermediate language.


3 Responses to WMAT Released – Web Mail Auth Tool For Testing Web Mail Logins

  1. Godwyn February 25, 2009 at 1:41 pm #

    I really want to know how this tool works and how to use it
    guess it would be a very helpful tool

  2. send9 February 25, 2009 at 11:03 pm #

    Godwyn: How it works? Just download it and run it. It’s written in Python, so you can read the source all you want.

    My question, though, is why this is limited to web mail. It looks like it can be pretty useful for brute forcing any form-based login.

  3. Ivan Markovic March 5, 2009 at 4:19 pm #

    @Godwyn, You have examples.

    @send9, I will release new version very soon. One will be only for webmail (with many more options) and second one will be for brute forcing any form-based login.