
jwt-hack
JSON Web Token Hack Toolkit

JSON Web Token Hack Toolkit

Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+…

Active Directory password filter featuring breached password checking and custom complexity rules

Correlates NTLM hashes, BloodHound data, and cracked passwords for Active Directory penetration testing. Imports NTDS.dit, syncs to Neo4j, analyzes…

Educational lab demonstrating CVE-2024-21413 exploitation in Outlook to leak NTLM hashes via malicious UNC links, with custom SMTP/POP3…

Python utility for automating CVE-2024-4956 path traversal exploitation with mass file extraction, plus custom Hashcat module for cracking Apache…

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

Decrypts FortiGate configuration secrets (CVE-2019-6693) for versions below 6.2.0, extracting encrypted passwords and keys from dumped configs using…

AES-256 encrypted password manager with scrypt/SHA256 key derivation, supporting create, edit, query, and master password change operations with…

A native backdoor module for Microsoft IIS (Internet Information Services)

Built a custom Virtual Machine, running Ubuntu 18.04.1 and Webmin 1.810. Using CVE-2019-15107 to exploit a backdoor in the Linux machine