
nlahoney
NLA Honeypot Associated Research

NLA Honeypot Associated Research

Radmin Server 3 credentials dumper/cracker

XMLRPC server for password cracking

CVE-2022-35513 | blink1-pass-decrypt

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP-based phishing email delivery, malicious RTF attachment generation, and…

This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE…

HTB Season 10 - Pterodactyl machine writeup. Medium Linux box covering CVE-2025-49132 (Pterodactyl Panel RCE) and CVE-2025-6018/6019 (udisks2…


A Golang implant that uses Slack as a command and control server

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

A native backdoor module for Microsoft IIS (Internet Information Services)

Hashtopolis - distributed password cracking with Hashcat

Browser-based password cracking toolkit with hash lookup, wordlist generation, rule-based attack simulation, and client-side hash cracking for…

Distributed brute-force password cracking system that parallelizes dictionary and crunch-based attacks across multiple machines via web and desktop…

Automatically grab and crack WPA-2 handshakes with distributed client-server architecture

Remote administration service which uses twitter as a command and control server