
CVE-2023-7028
Exploit for GitLab account takeover via CVE-2023-7028, demonstrating password reset bypass by injecting attacker email to receive reset token.

Exploit for GitLab account takeover via CVE-2023-7028, demonstrating password reset bypass by injecting attacker email to receive reset token.

Exploit for GitLab CVE-2023-7028: password reset bypass via dual email verification, allowing unauthorized account takeover. Includes affected…

Modular Java mail server supporting IMAP, SMTP, POP3, and JMAP with Docker deployment, distributed architecture, and CLI management for secure…

A JWT based API for managing users and issuing JWT tokens

Entra ID user enumeration and auth method discovery via the public GetCredentialType API


Zero-Knowledge Credential Sharing

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

Provides distributed enterprise VPN connectivity using OpenVPN, with centralized management, authentication, and encrypted tunnels for cloud and…

Modlishka. Reverse Proxy.

Trying to tame the three-headed dog.

Remote Desktop Protocol .NET Console Application for Authenticated Command Execution

PowerShell Pass The Hash Utils

Kerberos relaying and unconstrained delegation abuse toolkit

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

Kerberos relay framework for Windows environments enabling authentication relay, privilege escalation, and lateral movement via LDAP, SMB, HTTP, and…