
win-brute-logon
Crack any Microsoft Windows users password without any privilege (Guest account included)

Crack any Microsoft Windows users password without any privilege (Guest account included)

Payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy . Brutal is…

Detect and abuse risky SPNs


cve-2020-1472 复现利用及其exp

Security Research

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

cve-2020-1472_Tool collection

A simple implementation/code smash of a bunch of other repos

This is a combination of the zerologon_tester.py code (https://raw.githubusercontent.com/SecuraBV/CVE-2020-1472/master/zerologon_tester.py) and the…

Comprehensive penetration testing cheat sheet for PWK/OSCP exam preparation, covering privilege escalation, password cracking, payload generation,…

A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

Full penetration test report against `IP` (Ubuntu VM). Attack chain: directory enumeration → backup file discovery → password cracking → CMS file…

Zerologon Check and Exploit - Discovered by Tom Tervoort of Secura and expanded on @Dirkjanm's cve-2020-1472 coded example. This tool will check,…

Modified the test PoC from Secura, CVE-2020-1472, to change the machine password to null

McAfee Advanced Threat Defense ATD 4.6.x and earlier - Hardcoded root password

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

exploit of CVE-2022-0847 which directly remove password of the root account