
sandy
Release of the sandy framework.

Release of the sandy framework.

Mass bruteforce authentication of common services with common credentials.

Let's Snatch The Admin Panel Of Any Website In Seconds.

PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

POC of CVE-2014-0166 (WordPress cookie forgery vulnerability)

Educational Proof of Concept exploit for CVE-2024-25723, demonstrating unauthorized account takeover in ZenML via API password reset, with version…

Python exploit for CVE-2018-9995 targeting DVR/NVR devices with login bypass, supporting reconnaissance via Shodan and Zoomeye dorks.

Proof of Work of CVE-2023-23397 for vulnerable Microsoft Outlook client application.

VULNERAVEL CVE-2018-14847 - CREDENCIAIS EXTRAIDAS MIKROTIK EM PYTHON

Python exploit for CVE-2018-9995 that retrieves exposed DVR credentials by bypassing authentication on vulnerable web interfaces.

Step-by-step walkthrough of exploiting CVE-2024-21413 in Microsoft Outlook to bypass Protected View and leak NTLM credentials via Moniker Links,…

Decrypts passwords stored in SOS JobScheduler (S)FTP profiles by exploiting the use of the profile name as the 3DES encryption key, enabling recovery…

Educational lab demonstrating detection and mitigation of CVE-2023-32243 privilege escalation in WordPress Essential Addons for Elementor, using…

Python utility that reads accessible gMSA password blobs from Active Directory and extracts plaintext passwords for use in security audits and red…

A swiss army knife for pentesting networks

A collection of hacking tools, resources and references to practice ethical hacking.

BruteSploit is a collection of method for automated Generate, Bruteforce and Manipulation wordlist with interactive shell. That can be used during a…