
ad-password-protection
Active Directory password filter featuring breached password checking and custom complexity rules

Active Directory password filter featuring breached password checking and custom complexity rules

This repository contains a Proof of Concept (PoC) Python script for CVE-2025-58434, which enables attackers to change passwords of other users…

Remote timing attack exploit for Apache mod_auth_digest (CVE-2026-33006) that bypasses Digest authentication via a 33-layer temporal cascade,…

Generate passwords from the terminal

Low and slow password spraying tool, designed to spray on an interval over a long period of time

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

DifuseHQ Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient…

Password Lense: reveal character types in a password

Unverified Password Change (CWE-620)

Proof-of-concept for CVE-2025-25749 demonstrating weak password policy in HotelDruid 3.0.7, with automated test scripts and mitigation…

The hmac-bcrypt password hashing function

POC for CVE-2024-3183 (FreeIPA Rosting)

Fast offline auditing of Active Directory passwords using Python.

Python utility that reads accessible gMSA password blobs from Active Directory and extracts plaintext passwords for use in security audits and red…

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Simple HS256, HS384 & HS512 JWT token brute force cracker.

Use ESC1 to perform a makeshift DCSync and dump hashes