Skip to content

Latest commit

 

History

20 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

SmugglePwn - HTTP Request Smuggling Exploitation Framework

Python Version License Security

Professional-grade tool for detecting and exploiting Client-Side HTTP Request Smuggling vulnerabilities in Microsoft Exchange OWA and other web applications.

Features

Vulnerability Detection

  • CL.TE Detection with unique marker injection
  • Double/Triple Response Detection - strongest evidence of smuggling
  • Response Queuing Attacks - cross-user contamination demonstration
  • Out-of-Band Verification - Burp Collaborator/OAST integration

Exploitation

  • Interactive Email Spoofing - send emails from any sender with custom content
  • XSS Cache Poisoning - poison caches to compromise multiple users
  • Cookie Exfiltration - steal session cookies via XSS with real-time monitoring

Professional Tooling

  • Local POC Server - built-in HTTP server for receiving stolen cookies
  • Proxy Support - full proxy configuration with CONNECT method for HTTPS
  • Multi-Format Reporting - TXT, HTML, JSON, Markdown
  • Verbose Packet Inspection - full request/response visualization

Prerequisites

  • Python 3.7 or higher
  • No external dependencies required - all libraries are part of the Python standard library

Installation

git clone https://github.com/V3kt0r39/SmugglePwn.git
cd SmugglePwn
chmod +x hrs_exploit.py

Usage

Interactive Mode (Recommended)

python3 hrs_exploit.py email.example.com

Module Mode

python3 -m hrs email.example.com

Direct Mode (Non-Interactive)

python3 hrs_exploit.py email.example.com 443 \
  --session "ASP.NET_SessionId=abc123" \
  --collaborator "abc123.oastify.com" \
  --proxy "127.0.0.1:8080" \
  --no-interactive

CLI Options

Flag Description
target Target hostname (required)
port Target port (default: interactive selection)
--session Valid session cookie for email spoofing
--collaborator Burp Collaborator/OAST domain
--proxy Proxy server in host:port format
--no-interactive Skip interactive configuration
--verbose Enable verbose packet output
--output Report format: txt, html, json, md, all

Project Structure

SmugglePwn/
├── hrs/                        # Main package
│   ├── __init__.py             # Package init, version
│   ├── __main__.py             # python -m hrs entry point
│   ├── types.py                # Dataclasses: Config, TestResults
│   ├── constants.py            # Shared constants, templates
│   ├── output.py               # Colors, print helpers
│   ├── network.py              # Socket/SSL layer, payload building
│   ├── poc_server.py           # Local HTTP server for cookie exfil
│   ├── detectors.py            # Vulnerability detection tests
│   ├── exploits.py             # Email spoofing, XSS poisoning
│   ├── reports.py              # Report generation (TXT/HTML/JSON/MD)
│   ├── config.py               # Interactive configuration menu
│   └── cli.py                  # Argument parsing, orchestration
├── hrs_exploit.py              # Legacy entry point (backward compat)
├── README.md
├── LICENSE
└── .gitignore

Testing Methodology

  1. CL.TE Vulnerability Detection - Content-Length vs Transfer-Encoding desync with unique markers
  2. Double/Triple Response Detection - single request generating multiple responses
  3. Response Queuing Attack - cross-user contamination demonstration
  4. Collaborator OAST Verification - out-of-band DNS/HTTP callback
  5. Email Spoofing - interactive sender/recipient/subject/body configuration
  6. XSS Cache Poisoning - cookie exfiltration via reflected XSS

Report Generation

After testing, choose from:

  • Text - console-friendly detailed format
  • HTML - professional visual report with styling (recommended)
  • JSON - machine-readable for automation
  • Markdown - GitHub/GitLab friendly

Example Workflow

python3 hrs_exploit.py email.example.com

# Follow prompts:
# 1. Port: 443
# 2. Session: ASP.NET_SessionId=abc123 (optional)
# 3. Exfiltration: Local POC Server -> Port 9600
# 4. Proxy: skip
# 5. Verbose: VERBOSE

# Watch for:
# [!] CL.TE VULNERABILITY CONFIRMED
# [!] DOUBLE RESPONSE DETECTED
# [!] EMAIL SPOOFING SUCCESSFUL
# [!] XSS PAYLOAD REFLECTED

Legal Disclaimer

This tool is for authorized security testing only.

  • Use only on systems you own or have explicit permission to test
  • Ensure you have written authorization before testing any target
  • Follow all applicable laws and regulations

License

MIT License - see LICENSE

References

About

HTTP Request Smuggling & Client-Side Desync framework for Exchange OWA. CL.TE/TE.CL detection, email spoofing, cache poisoning.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages