Giter Club home page Giter Club logo

mailtools's Introduction

image

image image image visits

Community

XSS.is (Damagelab reborn) is one of the oldest underground forums with skilled and friendly members. Most likely there you will find help and new business partners. Welcome aboard!

Mail Tools

  • Fast as hell proxyless SMTP checker/validator. Converts mail:pass lists to valid smtp credentials.
  • Validol - email validator/debouncer that will save your ass. Remove strings with dangerous emails from files you provide at insane speed.
  • MadCat mailer. Just another multithreaded smtplib-based mailer. Worth giving it a try.
  • InboxStat - gives you statistics about list of inboxes by emails and urls. Also accepts search query, if you are looking for something specific. In development.
  • Pondy - email responder. Allows you to respond to every contact in list of mailboxes with your email. In development.
  • MKZMHTU - free bulk SMS sender through public gateways, with url randomisation and macros support. In development.

Educational materials

Don't be rude

I'm writing all these tools as part of my workflow, and giving them for free not cuz they are free, but cuz they works and do their job very very well. Please, respect my efforts and my time. Thank you.

These tools are still a work-in-progress

These tools are still a work-in-progress and should be mostly usable but may be not yet complete. Please file any bugs or feature requests as GitHub issues

[RU] Пишите, бл*ть в GitHub issues все баги, пожалуйста. Там их и порешаем. Не спамите личку. Я один, а вас очень много. Спасибо.

Legal Notices

You are ONLY allowed to use the following code for educational purposes. These scripts shall not be used for any kind of illegal activity nor law enforcement at any time (lol, really? Oh, for sure!). This restriction applies to all cases of usage, no matter whether the code as a whole or only parts of it are being used.

By downloading and/or using any part of the code and/or any file of this repository, you agree to this restriction without remarks.

mailtools's People

Contributors

aels avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

mailtools's Issues

mass-mailer - ломаются атачи

Проверил отправку в aol и outlook, файл в приложении всегда сломан, независимо от расширения файла
Пример с zip архивом:
attach_proof

Not working in Centos 7.

Installed this on Centos 7, but it keeps crushing.
Switched to Debian.

Need to update the commands for the installation

validor errro

I'm trying to the validol (get_safe_mails.py) and i get this error when running it 👍

\mailtools\remove-dangerous-emails\get_safe_mails.py", line 3, in
import threading, sys, time, re, os, signal, queue, resource, tempfile
ModuleNotFoundError: No module named 'resource'

th39: done with 11 mails 11 sent (0.1 mail/s)

Hey Geek,

When sending is complete i didn't get which server sent emails in the terminal, I just got like this:
th39: done with 11 mails 11 sent (0.1 mail/s)
The the39 I guess should be the server where emails are sent from but In my case, it just shows me that the with a number.

Thanks again for your great tool

expected string or bytes-like object

Выдает ошибку expected string or bytes-like object, и все что отмечено в Def не выводить почему то , питон 3.9 все модули потыкал )

         ╙█                           ╙                                         
          ╙     �[1mMadCat SMTP Checker & Cracker v23.02.19�[0m
                Made by �[1mAels�[0m for community: �[1mhttps://xss.is�[0m - forum of security professionals
                https://github.com/aels/mailtools
                https://t.me/freebug
	
�[1m[�[34mi�[37m] �[0musage: 
�[1m[�[37m?�[37m] �[0mpython3 C:\Users\obey\Desktop\11\smtp-checker\mail.py �[1mlist.txt�[0m [[email protected]] [ignored,email,domains] [start_from_line] [debug]
�[1m[�[37m?�[37m] �[0mpath to file with emails & passwords: 1.txt
SystemExit: �[1m[�[31mx�[37m] �[0m�[0;31mexpected string or bytes-like object�

Установил унбут полет тооооппппп , реально хорошая работа автора :)
Хотел бы узнать есть ли возможность во время работы остановить ее и сохранить остаток ?

Несколько замечаний и вопросов по коду smtp-checker

  • По autoconfigs

update_autoconfigs.py сохраняет в файл autoconfigs.txt, а mailpass2smtp.py подтягивает конфиг из autoconfigs_enriched.txt, к тому же не локально, а с репозитория. Возникают вопросы и по autoconfigs_enriched.txt. Для примера возьмём строчку
a1.net;securemail.a1.net:587,bsmtp.a1.net:587,forschung.a1.net:587;%EMAILADDRESS%

Откуда взялся хост forschung.a1.net? В базе его нет https://autoconfig.thunderbird.net/v1.1/a1.net. Как сгенерировать autoconfigs_enriched.txt? Парсер не выложен.

  • По dangerous_domains

Абсолютно непонятны элементы mx37\.m..p\.com и vm\d. Также непонятна концовка списка начиная с fucking-shit|please|kill-me-please..., почему эти домены зловредны?
Некорректный парсинг dangerous_domains, для теста взял asd@dESET.com:123456, получил
skipping domain: mail.deset.com (for deset.com)
Не нашёл подходящего примера, но было бы интересно узнать, как отработает фильтрация, когда в MX две записи, mail.company.com (норм) и mail.avast.com (ханипот АВ).

  • По bad_mail_servers

Для теста взял 5 строк

Все 5 уходят в ignored, а значит некорректно отрабатываются крайние случаи при фильтрации.

Почему пропускается TLS хендшейк в строке 152?
do_handshake_on_connect=False
Может ли быть ситуация, что без TLS хост-получатель дропнет коннект?

Не понял, как работает get_alive_neighbor. Что попадает в is_listening?

В массиве headers_arr указан MadCat, на основе этой сигнатуры антивирусные компании могут построить детектирование атаки, лучше убрать.

Бывают пропуски валида. На вход дал 13 валидных строк. На выходе иногда 11, иногда 12. Думаю, что это покрывается объёмами и повторными запусками, но недостаток имеет место.

На XSS ты предлагаешь поддерживать инструменты. Ты даже комменты в коде не пишешь. Как так?

Not Writing To File

I managed to get it to run, it checks the domains, finds good one and bad ones, prints the data in terminal but it doesn't save anything to dangerous and safe.txt

Also it runs fast, but once it gets the last email / row, it hangs there for a lot of time, with 2 threads open, it keeps on going forever - i have to ctrl+c to stop it.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.