
even-you-brutus
Dictionary Brute Force of the Mikrotik RouterOS 6.x Web Interface

Dictionary Brute Force of the Mikrotik RouterOS 6.x Web Interface

Python script that brute-forces Joomla administrator login credentials using wordlists, with proxy and verbose options for penetration testing.

Advisory for CVE-2026-77771, a 2FA bypass in the miniOrange WordPress plugin via session-scoped OTP lockout, with impact analysis and remediation…

Exploit for CVE-2021-42949 in HotelDruid v3.0.3, demonstrating predictable session token generation and authentication bypass via brute force.

ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade, convert, dissect and shuck authentication token based…

A brute force program to test weak accounts configured to access a JMX Registry


WPBF - a multithreaded WP brute forcer

Facebook brute forcer script

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

POC for CVE-2024-3183 (FreeIPA Rosting)

Exploit for CVE-2021-27342 vulnerability (telnet authentication brute-force protection bypass)

DifuseHQ Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient…

This is the exploit of CVE-2019-17240.

Possible Account Takeover | Brute Force Ability

elabFTW < 4.1.0 - account lockout bypass and login brute force