
HotelDruid-CVE-2021-42949
Exploit for CVE-2021-42949 in HotelDruid v3.0.3, demonstrating predictable session token generation and authentication bypass via brute force.

Exploit for CVE-2021-42949 in HotelDruid v3.0.3, demonstrating predictable session token generation and authentication bypass via brute force.

INSTA_CYBER is a Python-powered ethical hacking tool designed for educational and research purposes. Built by Muhammad Sabir Ali (INNO_CYBER), this…

ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade, convert, dissect and shuck authentication token based…

A brute force program to test weak accounts configured to access a JMX Registry


WPBF - a multithreaded WP brute forcer

Facebook brute forcer script

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

POC for CVE-2024-3183 (FreeIPA Rosting)

Exploit for CVE-2021-27342 vulnerability (telnet authentication brute-force protection bypass)

DifuseHQ Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient…

This is the exploit of CVE-2019-17240.

Possible Account Takeover | Brute Force Ability

elabFTW < 4.1.0 - account lockout bypass and login brute force

Bludit 3.9.2 - Auth Brute Force Mitigation Bypass. CVE-2019-17240

Exploit for CVE-2020-15367: brute-force authentication attack against Venki Supravizio BPM 10.1.2 login page, leveraging user enumeration to gain…