
hmac-bcrypt
The hmac-bcrypt password hashing function

The hmac-bcrypt password hashing function

Fast offline auditing of Active Directory passwords using Python.

Toolkit for attacking MS Kerberos implementations: extract SPN accounts, request and export tickets, crack service passwords, rewrite tickets for…

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Automated tool that hunts for world-readable passwords in Active Directory LDAP databases by leveraging Kerberos authentication and ldapsearch to…

Teamsniper is a tool for fetching keywords in a Microsoft Teams such as (passwords, emails, database, etc.).

Locky generates "really" strong yet easy to remember passwords.

Password Spraying Script detecting current and previous passwords of Active Directory User

Store and retrieve your passwords from a secure offline database. Check if your passwords has leaked previously to prevent targeted password reuse…

Crypt and decrypt the cisco enable 7 passwords

Generate passwords from the terminal

Remote timing attack exploit for Apache mod_auth_digest (CVE-2026-33006) that bypasses Digest authentication via a 33-layer temporal cascade,…

This repository contains a Proof of Concept (PoC) Python script for CVE-2025-58434, which enables attackers to change passwords of other users…

Latch plugin for OpenVPN Access Server enabling two-factor authentication (2FA) to secure VPN connections with time-based one-time passwords (TOTP).

PoC checker for CVE-2022-31749 exploiting a parameter injection vulnerability in WatchGuard SSH interface to exfiltrate hashed user passwords via FTP.

An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted…

Proof-of-concept for CVE-2021-3130: demonstrates credential exposure via HTML obfuscation bypass in Open-AudIT up to 4.0.2, revealing SSH, SNMP, and…