
gorilla
tool for generating wordlists or extending an existing one using mutations.

tool for generating wordlists or extending an existing one using mutations.

NLA Honeypot Associated Research

Windows常用程序密码读取工具:SharpDecryptPwd

Automated exploit for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple ≤2.2.9. Extracts admin credentials (username, email,…


Dump the saved wifi passwords for windows using regular expressions and python 3

Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

Remmina Password Decoder and scanner

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…

POC - CVE-2024–4956 - Nexus Repository Manager 3 Unauthenticated Path Traversal

CVE-2025-24071: NTLMv2 Hash Disclosure via .library-ms File

CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)

Full-lifecycle penetration test of a legacy Linux environment (Metasploitable 2) emulated on Apple Silicon. Demonstrating network reconnaissance, RCE…

First CTF successfully completed! This repo documents my walkthrough of TryHackMe's Simple CTF. It covers network reconnaissance (Nmap), web…

Exploit for CVE-2025-44203 targeting a race condition in HotelDruid 3.0.0/3.0.7 that leaks admin credentials and causes denial of service. Includes a…

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Unauthenticated time-based blind SQL injection exploit for NotificationX WordPress plugin (CVE-2024-1698) that extracts admin username and password…