
By-Poloss..-..CVE-2026-19125
Verified proof-of-concept exploiting the EthPress <= 2.3.5 unauthenticated authentication bypass, granting a WordPress administrator session via a…

Verified proof-of-concept exploiting the EthPress <= 2.3.5 unauthenticated authentication bypass, granting a WordPress administrator session via a…

Local-first encrypted password vault for Android with Master Password access, Recovery Key support, Autofill integration, and portable encrypted…

Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.

Audit and incident response tool for CVE-2026-41940 vulnerability

An LDAP based Active Directory user and group enumeration tool

Proof-of-Concept (PoC) for an authentication bypass vulnerability affecting applications using pac4j-jwt with JWE (JSON Web Encryption).

Authentication Bypass Vulnerability Apache OFBiz < 18.12.10.

Burp Suite extension to perform Kerberos authentication

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Password attacks and MFA validation against various endpoints in Azure and Office 365

Proof of Concept Utilities Developed to Research NTLM Relaying Attacks Targeting ADFS

Padding oracle exploit for Oracle Access Manager (CVE-2018-2879) enabling decryption of encrypted cookies and encryption of arbitrary plaintext for…

automated password spraying tool

Tool for assessing on-premises Microsoft servers authentication such as ADFS, Skype, Exchange, and RDWeb