
CVE-2018-13257
Proof-of-concept exploit for CVE-2018-13257 demonstrating CAS host header spoofing in Blackboard Learn to hijack user sessions via a malicious…
authenticationpenetration-testingphishing+3
1

Proof-of-concept exploit for CVE-2018-13257 demonstrating CAS host header spoofing in Blackboard Learn to hijack user sessions via a malicious…

An SSL Enabled Basic Auth Credential Harvester with a Word Document Template URL Injector

Credsleaker allows an attacker to craft a highly convincing credentials prompt using Windows Security, validate it against the DC and in turn leak it…

Gophish with Malicious Attachment and HTTP redirect support

Creates Fake Auth prompt to capture users plaintext passwords

⛏️ The extraction engine behind Maigret: turn any profile URL into a structured OSINT record across 150+ sites