striptls - poc implementation of STARTTLS stripping attacks.

striptls – poc implementation of STARTTLS stripping attacks.

striptls – poc implementation of STARTTLS stripping attacks.
SMTP
+ SMTP.StripFromCapabilities – server response capability patch
+ SMTP.StripWithInvalidResponseCode – client STARTTLS stripping, invalid response code
+ SMTP.UntrustedIntercept – STARTTLS interception (client and server talking ssl) (requires server.pem in pwd)
+ SMTP.StripWithTemporaryError
+ SMTP.StripWithError
POP3 (untested)
+ POP3.StripFromCapabilities
+ POP3.StripWithError
+ POP3.UntrustedIntercept
IMAP (untested)
+ IMAP.StripFromCapabilities
+ IMAP.StripWithError
+ IMAP.UntrustedIntercept
FTP (untested)
+ FTP.StripFromCapabilities
+ FTP.StripWithError
+ FTP.UntrustedIntercept
NNTP (untested)
+ NNTP.StripFromCapabilities
+ NNTP.StripWithError
+ NNTP.UntrustedIntercept
XMPP (untested)
+ XMPP.StripFromCapabilities

striptls - auditing proxy

striptls – auditing proxy

Usage:

Source : https://github.com/tintinweb