fzem – MUA (Mail User Agent) / Mail Client Fuzzer


fzem is a MUA (mail user agent) fuzzer that fuzzes MAIL/MIME email headers as well as how clients handle SMTP, POP and IMAP responses.

Purpose

fzem’s purpose is to fuzz MUAs as they process email content and handle server reponses.

How does it work?

fzem has the three main mail protocols implemented as well as mail/mime headers. Using these we can manipulate emails and responses to include fuzzing data from our fuzzing oracle or from the user.

A user can command fzem to run in various modes and perform differently in those modes.

  • Fuzz SMTP OK responses
  • Fuzz SMTP ERROR responses
  • Fuzz SMTP using custom fuzz data
  • Fuzz MAIL/MIME headers
  • Fuzz MAIL/MIME headers using custom fuzz data
  • Fuzz MAIL/MIME headers using custom headers
  • Fuzz POP3 OK responses
  • Fuzz POP3 ERROR responses
  • Fuzz POP3 using custom fuzz data
  • Fuzz IMAP4 OK responses
  • Fuzz IMAP4 ERROR responses
  • Fuzz IMAP4 using custom fuzz data

We can also choose a specific port to listen on (-P) and take advantage of the useful debug option (-D).

You can download fzem here:

fzem.tar.gz

Or read more here.

Posted in: Exploits/Vulnerabilities, Hacking Tools, Secure Coding

,


Latest Posts:


HELK - Open Source Threat Hunting Platform HELK – Open Source Threat Hunting Platform
The Hunting ELK or simply the HELK is an Open-Source Threat Hunting Platform with advanced analytics capabilities such as SQL declarative language, graphing etc
trape - OSINT Analysis Tool For People Tracking Trape – OSINT Analysis Tool For People Tracking
Trape is an OSINT analysis tool, which allows people to track and execute intelligent social engineering attacks in real-time.
Fuzzilli - JavaScript Engine Fuzzing Library Fuzzilli – JavaScript Engine Fuzzing Library
Fuzzilii is a JavaScript engine fuzzing library, it's a coverage-guided fuzzer for dynamic language interpreters based on a custom intermediate language.
OWASP APICheck - HTTP API DevSecOps Toolset OWASP APICheck – HTTP API DevSecOps Toolset
APICheck is an HTTP API DevSecOps toolset, it integrates existing tools, creates execution chains easily and is designed for integration with 3rd parties.
trident - Automated Password Spraying Tool trident – Automated Password Spraying Tool
The Trident project is an automated password spraying tool developed to be deployed on multiple cloud providers and provides advanced options around scheduling
tko-subs - Detect & Takeover Subdomains With Dead DNS Records tko-subs – Detect & Takeover Subdomains With Dead DNS Records
tko-subs is a tool that helps you to detect & takeover subdomains with dead DNS records, this could be dangling CNAMEs point to hosting services and more.


One Response to fzem – MUA (Mail User Agent) / Mail Client Fuzzer

  1. navin March 7, 2009 at 10:59 am #

    wow, and I thought this couldn’t be done!! Thanks krakowlabs!!