
keepass-exfil-forensics
Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

HTB_Enigma Security Assessment – Full pentest completed, chaining NFS disclosure, IMAPS password reuse, and OS Command Injection in OpenSTAManager…

CVE-2020-35848 impacts Cockpit-CMS v1.7 due to unsafe handling of user inputs in authentication mechanisms, leading to remote code execution. This…

CMS Made Simple < 2.2.10 - SQL Injection . Actual working version

Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.

CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥

📜 Scrape targeted wordlists for password cracking using CSS selectors

This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE…

A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

🔓Crack hashes using online rainbow & lookup table attack services, right from your terminal.

Decipher hashes using online rainbow & lookup table attack services.

Fast Steganography bruteforce tool written in Rust useful for CTF's

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash

Identify 300+ hash types instantly via CLI or web app. Prioritizes popular hashes, provides summaries, and integrates with HashCat and John the…

:zap: Worlds fastest steghide cracker, chewing through millions of passwords per second :zap:

Steganography brute-force utility to uncover hidden data inside files