
CVE-2023-27350
Proof-of-concept exploit for PaperCut CVE-2023-27350, chaining authentication bypass with built-in scripting abuse to achieve remote code execution…

Proof-of-concept exploit for PaperCut CVE-2023-27350, chaining authentication bypass with built-in scripting abuse to achieve remote code execution…

Proof-of-concept exploit for CVE-2020-35682: SAML authentication bypass in ManageEngine ServiceDesk Plus, enabling privilege escalation to…

Clone of w1.fi hostap.git - NOTE: This is not the main development location and pull requests for this repository are ignored. See the upstream…

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

PoC for the Veeam Recovery Orchestrator Authentication CVE-2024-29855

Animation Addons for Elementor Pro <= 1.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

A Powershell implementation of PrivExchange designed to run under the current user's context

Pass the Hash to a named pipe for token Impersonation

ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the…

This exploit is based on CVE-2023-27350 and was built upon the original exploit by horizon3ai and the Metasploit module.

Detect and abuse risky SPNs

Proof-of-concept exploit for CVE-2018-10933, demonstrating SSH authentication bypass via MSG_USERAUTH_SUCCESS injection. Includes Docker setup and…

The great CrackMapExec tool compiled for Windows

Tokend module for OS X with support for all cards supported by OpenSC

Fast, secure shell protocol built on HTTP/3, QUIC, and TLS 1.3. Supports OAuth2, OpenID Connect, and classical SSH authentication with UDP port…

A reverse proxy like nginx, built on pingora, simple and efficient.

Educational demo of CVE-2022-21449 Java ECDSA signature bypass using real and fake JWT tokens to illustrate the vulnerability and its impact on…

The Single Sign-On Multi-Factor portal for web apps. OpenID Certified™ and Post-Quantum Cryptography Ready.