
Flask-Unsign
Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

CMS Made Simple < 2.2.10 - SQL Injection . Actual working version

Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.

📜 Scrape targeted wordlists for password cracking using CSS selectors

A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

🔓Crack hashes using online rainbow & lookup table attack services, right from your terminal.

Decipher hashes using online rainbow & lookup table attack services.

Fast Steganography bruteforce tool written in Rust useful for CTF's

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash

Identify 300+ hash types instantly via CLI or web app. Prioritizes popular hashes, provides summaries, and integrates with HashCat and John the…

:zap: Worlds fastest steghide cracker, chewing through millions of passwords per second :zap:

Steganography brute-force utility to uncover hidden data inside files

BruteSploit is a collection of method for automated Generate, Bruteforce and Manipulation wordlist with interactive shell. That can be used during a…