
RedTeamScripts
Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Real-time phishing campaign back-office plugin for Zphisher, capturing credentials, checking account exposure via haveibeenpwned, and evaluating…

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC

The plugin, used as a companion for the Discy and Himer themes, does not sanitise and escape a parameter on its reset password form which makes it…

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Python script that acts like the original sudo binary to fool users into entering their passwords

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

cve-2024-21413

CVE-2023-23397 C# PoC

Script in Go that analyzes a list of passwords based on in its entropy and weak passwords from a dictionary. Useful for penetration tests and…