Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
iDict — PHP-based iCloud Apple ID dictionary attack tool that bypasses account lockout and secondary authentication to brute-force credentials. | Kitploit
Tools/GitHubGitHub/pr0x13/idict
Password AttacksExploitationWeb Application ExploitationWeb SecurityPenetration TestingAuthentication
GitHubpr0x13/idict

iDict

PHP-based iCloud Apple ID dictionary attack tool that bypasses account lockout and secondary authentication to brute-force credentials.

View Repository
9015443 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Disclaimer: Do whatever you want with this code as long as you give me credit (@Pr0x13) Check and make sure its legal in your country to use this tool before doing so. I'm not responsible for any damage done whatsoever to anyones iCloud account or iDevice. I Didn't exploit any accounts while writing this, as well i didn't even test it out (Hope it works lol). I merely observed and reported.

Install: Put in HtDocs Folder in your Xampp installation. Install cUrl for your OS Navigate to http://127.0.0.1/iDict/ in your web browser (preferably Firefox, Chrome, or Safari). Wordlist.txt is from iBrute and it satisfies iCloud password Requirements It's been reported if icloud server responds with an error restart xampp or your computer

-=Reports coming in that Server is now Patched with Rate Limiter=- -=Server Fully Patched, Discontinue use if you don't want to lock your account!!=-

What is this? A 100% Working iCloud Apple ID Dictionary attack that bypasses Account Lockout restrictions and Secondary Authentication on any account.

What this isn't: A bypass or fully automated removal

Why? This bug is painfully obvious and was only a matter of time before it was privately used for malicious or nefarious activities, I publicly disclosed it so apple will patch it.

@Pr0x13

Download Tool