DropoutJeep is a phishing-simulation and red-team platform with 80-plus utility modules spanning OSINT, pretext generation, payload crafting, C2, exfiltration, evasion, persistence, and deliverability. This memo covers why it exists, why it keeps growing, and why its authors now read Gmail spam-filter documentation for fun.
An unauthenticated stored XSS in a popular CMS extension, found while diffing an unrelated
patch. Vendor and plugin name withheld pending coordinated disclosure. Full writeup, PoC,
and CVE reference land here the day the fix ships.
Recon methodology and chain automation: one unauthenticated request against a Grandstream GXP phone
becomes a root shell on the UCM PBX. Blind-oracle SQLi, credential reuse graphs, and the
stdlib-only Python script that compresses the whole chain into thirty seconds.