
JKS-private-key-cracker-hashcat
Nail in the JKS coffin - Cracking passwords of private key entries in a JKS file

Nail in the JKS coffin - Cracking passwords of private key entries in a JKS file

Proof of Concept for WatchGuard Authenticated Arbitrary File Read (CVE-2022-31749)

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure


cve-2024-21413

CVE-2023-23397 C# PoC

John the Ripper jumbo - advanced offline password cracker, which supports hundreds of hash and cipher types, and runs on many operating systems,…

CVE-2024–27630 Reference

Bcrypt hash cracker for penetration testing and password recovery. Decrypts Bcrypt hashes using dictionary or brute-force methods.

Proof-of-concept for CSV injection in GNOME Time Tracker 3.0.2, demonstrating arbitrary code execution via crafted .tsv files and formula injection.

Proof-of-concept for CVE-2022-45782: predictable dotCMS password-reset tokens, with a token cracker and full exploit chain.

Domain Password Audit Tool for Pentesters


Python utility for automating CVE-2024-4956 path traversal exploitation with mass file extraction, plus custom Hashcat module for cracking Apache…

Python PoC for CVE-2023-6063, an unauthenticated time-based blind SQL injection in WP Fastest Cache <=1.2.2, extracting WordPress password hashes and…

Python exploit for CVE-2019-9053 SQL injection in CMS Made Simple 2.2.10 with password hash cracking and user enumeration capabilities.

Recursively scan folders with VirusTotal API to detect malware. Features hash lookup, CSV export, real-time progress, and rate-limit handling for…

Exploit for CVE-2019-9053, an unauthenticated SQL injection in CMS Made Simple 2.2.9, that extracts admin credentials and optionally cracks the…