
CVE-2024-1698-Exploit
This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.

This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.

An #OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and…

Check-LocalAdminHash is a PowerShell tool that attempts to authenticate to multiple hosts over either WMI or SMB using a password hash to determine…

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Search tool to find specific files containing specific words, i.e. files containing passwords..

Let's find someone's account

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

SSHBuster is a powerful command-line SSH brute-forcing tool designed for ethical hacking and penetration testing. It performs dictionary-based…

Know the dangers of credential reuse attacks.

My collection of nmap NSE scripts

Security reconnaissance and assessment tool for identifying potentially exposed IP cameras by analyzing open ports, service configurations, and…

Browser-based password cracking toolkit with hash lookup, wordlist generation, rule-based attack simulation, and client-side hash cracking for…

Web Application Vulnerability Scanner

Tool for RTSP that brute-forces routes and credentials, makes screenshots!

Mini-paper on CVE-2017-2751, HP EFI password extraction.

Original PoC for CVE-2023-32784

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.