
Zphisher-GUI-Back_office
Real-time phishing campaign back-office plugin for Zphisher, capturing credentials, checking account exposure via haveibeenpwned, and evaluating…

Real-time phishing campaign back-office plugin for Zphisher, capturing credentials, checking account exposure via haveibeenpwned, and evaluating…

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC

The plugin, used as a companion for the Discy and Himer themes, does not sanitise and escape a parameter on its reset password form which makes it…

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Python script that acts like the original sudo binary to fool users into entering their passwords

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

cve-2024-21413

CVE-2023-23397 C# PoC

Script in Go that analyzes a list of passwords based on in its entropy and weak passwords from a dictionary. Useful for penetration tests and…