
DPAPISnoop
A C# tool to output crackable DPAPI hashes from user MasterKeys

A C# tool to output crackable DPAPI hashes from user MasterKeys

NLA Honeypot Associated Research

LSTAR - CobaltStrike Translated to EN

An authorized remote user with access or knowledge of the standard encryption key can gain access and decrypt the FortiOS backup files and all…

Penetration test walkthrough on a vulnerable Ubuntu VM. Exploited the ProFTPD 1.3.3c backdoor (CVE-2010-4221) to gain root access and capture the…


DifuseHQ Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient…

Moodle 4.5.0-4.5.2 Unauthenticated REST API User Data Exposure via Stack Trace Args Leak | CVSS 7.5



Technical write-up on CVE-2024-21413 (Moniker Link vulnerability)

Blind SQL injection brute force.

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

Improved code of Daniele Scanu SQL Injection exploit

Exploit for CVE-2025-2011

Python toolkit for decrypting AES-256 and cracking PBKDF2 passwords from Grafana databases usually paired with (CVE-2021-43798)


WiFi Penetration Testing Guide