
fakelogonscreen
Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

The plugin, used as a companion for the Discy and Himer themes, does not sanitise and escape a parameter on its reset password form which makes it…

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Script in Go that analyzes a list of passwords based on in its entropy and weak passwords from a dictionary. Useful for penetration tests and…

cve-2024-21413

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

Real-time phishing campaign back-office plugin for Zphisher, capturing credentials, checking account exposure via haveibeenpwned, and evaluating…

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

Python script that acts like the original sudo binary to fool users into entering their passwords

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

CVE-2023-23397 C# PoC