
pwn_jenkins
Notes about attacking Jenkins servers

Notes about attacking Jenkins servers

PoC exploit for CVE-2025-24071, a Windows File Explorer spoofing vulnerability that leaks NTLM hashes via malicious .library-ms files in RAR/ZIP…

Python Script to Crack Zip Password with Dictionary attack and also use Crunch as Pipeline

Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…

Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability

Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

Description and public exploit for CVE-2020-12712

Exploit for CVE-2024-46987 path traversal in Camaleon CMS enabling arbitrary file download and automated SSH key extraction via brute-force.

Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.

SSH brute-force tool targeting jailbroken iPhones with default 'alpine' password, featuring network scanning, wordlist-based cracking, and file…

Execute a brute force attack with Steghide to file with hide information and password established

Python-based exploit for CVE-2022-31890 in osTicket support ticketing system, enabling credential dumping via nickname and password enumeration…

Exploit for CVE-2019-17662 (ThinVNC 1.0b1)

Exploit For CVE-2019-17662

-> Password List Generator for Brute Force.

Multi-threaded password recovery tool for RAR, ZIP, PDF, and Linux shadow files using dictionary and brute-force methods with configurable character…

CVE-2025-2539 - WordPress File Away <= 3.9.9.0.1 - Arbitrary File Read