
LabS4U2Self
Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

AuthBypass & Auto Backdooring Devices

PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security…

Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

Owa Valid Login Checker

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

Brute Force Wordpress Blogs.

Proof-of-concept exploit for CVE-2024-10508: unauthenticated privilege escalation via password recovery bypass in RegistrationMagic WordPress plugin…

Macally WIFISD2

Modifed ver of the original exploit to save some times on password reseting for unprivileged user

Fast Modular Web Interfaces Bruteforcer

This vulnerability allows an attacker to bypass the credentials brute-force prevention mechanism of the Embedded Web Server (interface) of more than…

This tool tests WordPress installations for XML-RPC authentication vulnerabilities.

A simple super fast django reusable app that blocks people from brute forcing login attempts

Interactive password profiler that generates targeted wordlists by gathering personal details about a user, used for penetration testing and forensic…

Python PoC exploit for CVE-2023-6329 authentication bypass in Control iD iDSecure. Reconstructs admin credentials via predictable password derivation…

User enumeration and password spraying tool for testing Azure AD