
web2py-e94946d-CVE-2016-3957
web2py/web2py @ e94946d

web2py/web2py @ e94946d
HMAC Implementation Example and Explanation

Proof-of-concept exploit demonstrating OAuth2 authorization code reuse in XenForo before 2.3.13, allowing token replay and multiple token families.

Non-intrusive version-based vulnerability scanner for CVE-2026-4282 (Keycloak SingleUseObjectProvider isolation flaw enabling authorization code…

Documents CP PLUS EZ-P21 IP camera CVEs: arbitrary code execution via debug feature and improper authentication of HTTP endpoints, with responsible…

A Powershell implementation of PrivExchange designed to run under the current user's context

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

A JWT based API for managing users and issuing JWT tokens

Penetration tests guide based on OWASP including test cases, resources and examples.

An LDAP based Active Directory user and group enumeration tool

One day based on https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

Knocker, a knock based access control service for your homelab

a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket

ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade, convert, dissect and shuck authentication token based…

A Python based ingestor for BloodHound

This exploit is based on CVE-2023-27350 and was built upon the original exploit by horizon3ai and the Metasploit module.

CVE-2025-52691 PoC: Based on watchtowr's article WT-2026-0001 about an authentication bypass exploit, this one is a functional Python attack script.