


Software to identify the different types of hashes -

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

Brute-force scraper for HackerOne disclosed reports via their public API, collecting report IDs, links, titles, and states for security research and…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

cve-2020-1472 复现利用及其exp

Making Favicon.ico based Recon Great again !

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

CVE-2023-23397 C# PoC

This script complements the results obtained through the keepass-password-dumper tool when exploiting the CVE-2023-32784 vulnerability affecting…

针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)

Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass Exploit/PoC

Exploit for CVE-2024-21754 targeting insufficient password hashing in FortiOS and FortiProxy, enabling privileged attackers to decrypt backup files…

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)

Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473

This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made…

POC for CVE-2024-3183 (FreeIPA Rosting)