
even-you-brutus
Dictionary Brute Force of the Mikrotik RouterOS 6.x Web Interface

Dictionary Brute Force of the Mikrotik RouterOS 6.x Web Interface

Python script that brute-forces Joomla administrator login credentials using wordlists, with proxy and verbose options for penetration testing.

8-14 character Hashcat masks based on analysis of 3.2 million NTLM hashes cracked while pentesting

Markov model-based password guesser in C that enumerates candidates by probability, generating most likely passwords first for hash cracking via…

Python/Go framework that generates SQL injection PoC requests, automates sqlmap attacks, and manages modular exploit scripts with parameter detection…

Offset Independent Credential Extraction Tool

Proof-of-concept decrypting Araxis Merge's DPAPI-protected server credentials (CVE-2026-92680), demonstrating insufficiently protected credential…

Python 3 exploit for CVE-2019-9053, a CMS Made Simple SQL injection vulnerability, enabling credential extraction via time-based blind SQLi and…

Python PoC for CVE-2023-6063, an unauthenticated time-based blind SQL injection in WP Fastest Cache <=1.2.2, extracting WordPress password hashes and…

Web-based GUI for Hashcat that simplifies password cracking with session management, mask generation, wordlist support, and multi-user access.

Plug-and-play hashcat wrapper that cracks password hashes using preconfigured dictionary, rule-based, combinator, and mask attacks, supporting dozens…

C# version of NTLMRawUnHide

A C# tool to output crackable DPAPI hashes from user MasterKeys

ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade, convert, dissect and shuck authentication token based…

MikroTik Password Recovery Tool

Python3 implementation for converting Artemis PBKDF2WithHmacSHA1 hashes to hashcat format

Very Slow HMAC Key Bruteforcer

Automated Cisco SNMP Enumeration, Brute Force, Configuration Download and Password Cracking