
WPCracker
WordPress pentest tool

WordPress pentest tool

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

a very fast brute force webshell password tool

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Brute forcer and shell deployer for WildFly

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

Go-based brute-force exploit tool targeting Hikvision cameras vulnerable to CVE-2021-36260, with multi-threaded scanning and configurable…


This tool can be used to brute discover GET and POST parameters

Brute Force Wordpress Blogs.

CTF wargame platform featuring Unicode bypass exploitation (CVE-2015-9238), flag file segmentation, brute force delay, and password hashing for…

Proof-of-concept exploit for CVE-2021-29156, an LDAP injection vulnerability in ForgeRock OpenAM v13.0.0, enabling character-by-character brute force…

CVE-2021-46366: Credential Bruteforce Attack via CSRF + Open Redirect in Magnolia CMS


CrackerJack / Hashcat Web Interface / Context Information Security

Facebook brute forcer script

Brute Hikvision CAMS with CVE-2021-36260 Exploit