
metasploit-ldapnightmare
SafeBreaches CVE-2024-49113 POC(LdapNightmare) Integrated into Metasploit

SafeBreaches CVE-2024-49113 POC(LdapNightmare) Integrated into Metasploit

C2 tool routing Cobalt Strike beacon data over LDAP user attributes for stealthy command-and-control in segmented networks.

CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.

Hands-on lab exercise for exploiting Log4Shell (CVE-2021-44228) with JNDI injection, LDAP referral servers, and reverse shell payloads. Includes…

Proof-of-concept for Log4Shell (CVE-2021-44228) demonstrating JNDI-based remote code execution via LDAP and HTTP servers.

Apache Log4j 2 a remote code execution vulnerability via the ldap JNDI parser.

Proof-of-concept exploit for Log4Shell (CVE-2021-44228) demonstrating remote code execution via JNDI injection, including payload compilation, LDAP…

A malicious LDAP server for JNDI injection attacks

Generates workable JNDI injection links and deserialization payloads with 80+ gadgets, supporting RMI, LDAP, and HTTP servers for automated…

Technical write-up and proof-of-concept for CVE-2022-44666, a Windows Contacts syslink control href attribute escape vulnerability enabling remote…

CVE-2024-49112 LDAP RCE PoC and Metasploit Module

Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...

Step-by-step reproduction guide for CVE-2021-44228 (Log4Shell) with JDK 8u20, vulnerable Log4j 2.14.1, marshalsec LDAP server, and custom payload…

Helpers, vulnerable applications, and exploit examples for CVE-2021-44228 (Log4Shell). Includes LDAP exfiltration server, RMI deserialization…

Demonstrates Log4Shell (CVE-2021-44228) exploitation with LDAP server, malicious JNDI payload, and vulnerable Spring Boot application for security…

Exploit for CVE-2024-49112, a critical Windows LDAP RCE vulnerability, triggering a crash via crafted Netlogon and LDAP interactions.

Educational demonstration of the Log4Shell vulnerability (CVE-2021-44228) with JNDI LDAP payloads for experimental testing on your own systems.

Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889