
CVE-2025-33073-checker
This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…

This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

Kerberos relaying and unconstrained delegation abuse toolkit

[UNSUPPORTED] A small tool to turn any entered passphrase into a strong secure password, allowing you to easily use different strong passwords for…

Detection tool for cPanel/WHM CVE-2026-41940 (CRLF injection auth bypass). Verify vulnerability on servers you own or have permission to test. For…

A little toolbox to play with Microsoft Kerberos in C

This is the exploit of CVE-2019-17240.

Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.

CVE-2020-13941: Abusing UNC Paths in Windows Environments in Apache Solr

pam_pkcs11 Bugfix

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

This vulnerability allows both authenticated and unauthenticated remote attackers to execute remote code on vulnerable FreePBX instances. These…

ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the…

Proof-of-Concept tool to authenticate to an LDAP/S server with a certificate through Schannel

Enumerate usernames on a domain where you have no creds by using SMB Relay with low priv.

LifterLMS <= 3.34.5 - Unauthenticated Options Import

Fast offline auditing of Active Directory passwords using Python.