RickGeex / ProxyLogon
ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin. We have also chained this bug with another post-auth arbitrary-file-write vulnerability, CVE-2021-27065, to get code execution.
☆31Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for ProxyLogon
- PickleC2 is a post-exploitation and lateral movements framework☆83Updated 3 years ago
- CVE-2021-26855: PoC (Not a HoneyPoC for once!)☆27Updated 3 years ago
- Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.☆45Updated 3 years ago
- Stealthy Stand Alone PHP Web Shell☆33Updated 5 years ago
- client-side prototype pullution vulnerability scanner☆46Updated 3 years ago
- Writeup of CVE-2020-15906☆44Updated 4 years ago
- NSE script to detect ProxyOracle☆14Updated 3 years ago
- Port forwarding via MSRPC (445/tcp) [WIP]☆31Updated 3 years ago
- SMBGhost (CVE-2020-0796) and SMBleed (CVE-2020-1206) Scanner☆46Updated 4 years ago
- ☆38Updated 4 years ago
- Passwordless RDP Session Hijacking☆63Updated 3 years ago
- DO NOT RUN THIS.☆47Updated 3 years ago
- Metasploit module for massive Denial of Service using #Bluekeep vector.☆25Updated 5 years ago
- ☆69Updated 3 years ago
- "Powershell script assisting with domain enumerating and in finding quick wins" - Basically written while doing the 'Advanced Red Team' l…☆79Updated 3 years ago
- Microsoft Exchange password spray tool with proxy support.☆40Updated 3 years ago
- Execute Mimikatz with different technique☆50Updated 3 years ago
- Generate image payloads in JS to bypass filters☆39Updated 3 years ago
- SMB Auto Relay provides the automation of SMB/NTLM Relay technique for pentesting and red teaming exercises in active directory environme…☆47Updated 3 years ago
- PoC CVE-2020-6308☆34Updated 3 years ago
- Windows TCPIP Finger Command / C2 Channel and Bypassing Security Software☆65Updated last year
- SonicWALL SSL-VPN Web Server Vulnerable Exploit☆46Updated 3 years ago
- Red Team tool for exfiltrating the target organization's Google People Directory that you have access to, via Google's API.☆59Updated 3 years ago
- ☆99Updated 3 years ago
- Log4j2 CVE-2021-44228 revshell, ofc it suck!!☆19Updated 2 years ago
- In progress persistent download/upload/execution tool using Windows BITS.☆42Updated 3 years ago
- C# tool to discover low hanging fruits☆89Updated last year
- PoC exploit code for CVE-2021-26855☆17Updated 3 years ago
- Nmap script to check vulnerability CVE-2021-21972☆28Updated 3 years ago