
Kaonashi
Curated wordlists, hashcat rules, and masks derived from billions of real passwords, with statistical analysis and research slides from RootedCON…

Curated wordlists, hashcat rules, and masks derived from billions of real passwords, with statistical analysis and research slides from RootedCON…

Local Linux enumeration script that identifies privilege escalation vectors including misconfigurations, world-writable files, clear-text passwords,…

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

An authorized remote user with access or knowledge of the standard encryption key can gain access and decrypt the FortiOS backup files and all…

Git All the Payloads! A collection of web attack payloads.

Small script to retrieve passwords from many types of Moxa device, including NPort, OnCell, MGate, etc.

Open-source tool to bypass windows and linux passwords from bootable usb

Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!

OWASP Passfault evaluates passwords and enforces password policy in a completely different way.

The Heartbleed bug `CVE-2014-0160` is a severe implementation flaw in the OpenSSL library, which enables attackers to steal data from the memory of…

This project offers a straightforward solution for retrieving forgotten PDF passwords using Google Colab. With just five simple steps, it efficiently…

Mountable Rails engine providing 24+ cybersecurity escape room scenarios with randomized passwords, JIT-compiled NPC dialogue, and RESTful API for…

Python script for trying default passwords for some TP-Link Hotspots

Password Strength Evaluator is a tool to evaluate the strength of passwords and provide recommendations to improve their security.

Proof of Concept (PoC) for a stack-based buffer overflow in Steghide 0.5.1. Demonstrates how long file paths trigger a crash (DoS) and leak sensitive…

Proof-of-concept for CVE-2025-25749 demonstrating weak password policy in HotelDruid 3.0.7, with automated test scripts and mitigation…

An exploitation tool to extract passwords using CVE-2015-5995.

Proof-of-concept exploit for CVE-2025-48932, a SQL injection in Invision Community <= 4.7.20. Extracts admin credentials and resets passwords via…