
windows-coerced-authentication-methods
A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various…

A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various…

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

The DCERPC only printerbug.py version


A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

Simple PoC in PowerShell for CVE-2023-23397

ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the…

Monitors Asterisk authentication logs and automatically bans IPs with repeated failed login attempts using iptables, with configurable thresholds and…

This is poc of CVE-2022-46169 authentication bypass and remote code execution

Leveraging it is a simple matter of presenting the server with the SSH2_MSG_USERAUTH_SUCCESS message, which shows that the login already occurred…

Authentication Bypass Vulnerability — CVE-2024–4358 — Telerik Report Server 2024

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to…

Mikrotik 0day Credential Disclosure Scanner

CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) RCE POC

Analysis of a logic vulnerability in the macOS SSH client leading to client passphrase exposure to a local attacker

python2.7 script for JWT generation

Unverified Password Change (CWE-620)