
Bludit-CVE-2019-17240-Fork
Better version of rastating.github.io/bludit-brute-force-mitigation-bypass/

Better version of rastating.github.io/bludit-brute-force-mitigation-bypass/

Exploit for CVE-2020-15367: brute-force authentication attack against Venki Supravizio BPM 10.1.2 login page, leveraging user enumeration to gain…

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

Proof-of-concept exploit for CVE-2023-34732 demonstrating authenticated function abuse in Flytxt NEON-dX to brute-force and reset user passwords,…

Exploit for CVE-2014-0195

Detects NTLM authentication status by checking LmCompatibilityLevel registry value to assess exposure to CVE-2024-43451 and mitigate credential relay…

Kraker is a distributed password brute-force system that focused on easy use.

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

Hidden AP with Deterministic Credentials

Attempts to exploit CVE-2012-3137 on vulnerable Oracle servers

Exploit for CVE-2024-21754 targeting insufficient password hashing in FortiOS and FortiProxy, enabling privileged attackers to decrypt backup files…

Blind SQL injection brute force.

Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield

elabFTW < 4.1.0 - account lockout bypass and login brute force

Proof-of-concept exploit for user enumeration vulnerability in Supravizio BPM 10.1.2 via password recovery response differences, enabling brute force…

Proof-of-concept for CVE-2024-53591, demonstrating domain enumeration via brute force on Seclore's login page to identify internal services.

POC for CVE-2024-3183 (FreeIPA Rosting)

User Enumeration vulnerability in Kaiten (workflow management system)