Professional-grade tool for detecting and exploiting Client-Side HTTP Request Smuggling vulnerabilities in Microsoft Exchange OWA and other web applications.
- CL.TE Detection with unique marker injection
- Double/Triple Response Detection - strongest evidence of smuggling
- Response Queuing Attacks - cross-user contamination demonstration
- Out-of-Band Verification - Burp Collaborator/OAST integration
- Interactive Email Spoofing - send emails from any sender with custom content
- XSS Cache Poisoning - poison caches to compromise multiple users
- Cookie Exfiltration - steal session cookies via XSS with real-time monitoring
- Local POC Server - built-in HTTP server for receiving stolen cookies
- Proxy Support - full proxy configuration with CONNECT method for HTTPS
- Multi-Format Reporting - TXT, HTML, JSON, Markdown
- Verbose Packet Inspection - full request/response visualization
- Python 3.7 or higher
- No external dependencies required - all libraries are part of the Python standard library
git clone https://github.com/V3kt0r39/SmugglePwn.git
cd SmugglePwn
chmod +x hrs_exploit.pypython3 hrs_exploit.py email.example.compython3 -m hrs email.example.compython3 hrs_exploit.py email.example.com 443 \
--session "ASP.NET_SessionId=abc123" \
--collaborator "abc123.oastify.com" \
--proxy "127.0.0.1:8080" \
--no-interactive| Flag | Description |
|---|---|
target |
Target hostname (required) |
port |
Target port (default: interactive selection) |
--session |
Valid session cookie for email spoofing |
--collaborator |
Burp Collaborator/OAST domain |
--proxy |
Proxy server in host:port format |
--no-interactive |
Skip interactive configuration |
--verbose |
Enable verbose packet output |
--output |
Report format: txt, html, json, md, all |
SmugglePwn/
├── hrs/ # Main package
│ ├── __init__.py # Package init, version
│ ├── __main__.py # python -m hrs entry point
│ ├── types.py # Dataclasses: Config, TestResults
│ ├── constants.py # Shared constants, templates
│ ├── output.py # Colors, print helpers
│ ├── network.py # Socket/SSL layer, payload building
│ ├── poc_server.py # Local HTTP server for cookie exfil
│ ├── detectors.py # Vulnerability detection tests
│ ├── exploits.py # Email spoofing, XSS poisoning
│ ├── reports.py # Report generation (TXT/HTML/JSON/MD)
│ ├── config.py # Interactive configuration menu
│ └── cli.py # Argument parsing, orchestration
├── hrs_exploit.py # Legacy entry point (backward compat)
├── README.md
├── LICENSE
└── .gitignore
- CL.TE Vulnerability Detection - Content-Length vs Transfer-Encoding desync with unique markers
- Double/Triple Response Detection - single request generating multiple responses
- Response Queuing Attack - cross-user contamination demonstration
- Collaborator OAST Verification - out-of-band DNS/HTTP callback
- Email Spoofing - interactive sender/recipient/subject/body configuration
- XSS Cache Poisoning - cookie exfiltration via reflected XSS
After testing, choose from:
- Text - console-friendly detailed format
- HTML - professional visual report with styling (recommended)
- JSON - machine-readable for automation
- Markdown - GitHub/GitLab friendly
python3 hrs_exploit.py email.example.com
# Follow prompts:
# 1. Port: 443
# 2. Session: ASP.NET_SessionId=abc123 (optional)
# 3. Exfiltration: Local POC Server -> Port 9600
# 4. Proxy: skip
# 5. Verbose: VERBOSE
# Watch for:
# [!] CL.TE VULNERABILITY CONFIRMED
# [!] DOUBLE RESPONSE DETECTED
# [!] EMAIL SPOOFING SUCCESSFUL
# [!] XSS PAYLOAD REFLECTEDThis tool is for authorized security testing only.
- Use only on systems you own or have explicit permission to test
- Ensure you have written authorization before testing any target
- Follow all applicable laws and regulations
MIT License - see LICENSE