
UltraRealy_with_CVE-2019-1040
Updated version for the tool UltraRealy with support of the CVE-2019-1040 exploit

Updated version for the tool UltraRealy with support of the CVE-2019-1040 exploit

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote…

Dump Kerberos tickets from the KCM database of SSSD

C library implementing the SSH protocol for secure remote access, authentication, and encrypted communication. Includes fuzzing support via OSS-Fuzz…

The easiest, most secure way to use WireGuard and 2FA.

Proof-of-concept exploit for CVE-2024-55591, enabling unauthenticated WebSocket CLI access to FortiOS devices, with interactive shell and admin…

Perfom With Massive Authentication Bypass In PaperCut MF/NG

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

A tool to perform Kerberos pre-auth bruteforcing

CVE-2026-8181 PoC: Burst Statistics (3.4.0–3.4.1.1) authentication bypass. Python tool — single & multi-target scans, threaded workers, TXT reports.…

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security…

Simple and sane cryptographic wrapper library.

bypass all stages of the password reset flow

Python-based scanner that detects CVE-2026-24061 in GNU Inetutils telnetd, allowing batch testing of multiple targets for the authentication bypass…

CVE-2025-40554 Exploitation

Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers…