RickGeex / ProxyLogon
ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin. We have also chained this bug with another post-auth arbitrary-file-write vulnerability, CVE-2021-27065, to get code execution.
☆31Updated 4 years ago
Alternatives and similar repositories for ProxyLogon
Users that are interested in ProxyLogon are comparing it to the libraries listed below
Sorting:
- CVE-2021-26855: PoC (Not a HoneyPoC for once!)☆27Updated 3 weeks ago
- DO NOT RUN THIS.☆47Updated 3 years ago
- Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.☆47Updated 4 years ago
- PickleC2 is a post-exploitation and lateral movements framework☆91Updated 3 years ago
- Windows TCPIP Finger Command / C2 Channel and Bypassing Security Software☆66Updated last year
- Stealthy Stand Alone PHP Web Shell☆33Updated 5 years ago
- NSE script to detect ProxyOracle☆14Updated 3 years ago
- Writeup of CVE-2020-15906☆48Updated 4 years ago
- Invoke-SocksProxy is a PowerShell script designed to create reverse proxies.☆49Updated 4 years ago
- ☆99Updated 4 years ago
- client-side prototype pullution vulnerability scanner☆46Updated 3 years ago
- A web shell for pivoting and lateral movement☆34Updated 7 years ago
- ☆71Updated 4 years ago
- CVE-2021-40444☆65Updated 3 years ago
- Microsoft Exchange password spray tool with proxy support.☆40Updated 3 years ago
- SMB Auto Relay provides the automation of SMB/NTLM Relay technique for pentesting and red teaming exercises in active directory environme…☆47Updated 4 years ago
- SonicWALL SSL-VPN Web Server Vulnerable Exploit☆48Updated 4 years ago
- "Powershell script assisting with domain enumerating and in finding quick wins" - Basically written while doing the 'Advanced Red Team' l…☆81Updated 3 years ago
- Port forwarding via MSRPC (445/tcp) [WIP]☆32Updated 3 years ago
- DLL to open up calc.exe to demonstrate that you injected DLLs☆23Updated 4 years ago
- Execute Mimikatz with different technique☆51Updated 3 years ago
- ☆38Updated 5 years ago
- Local File Inclusion Burp-Suite Intruder Payload Generator Plugin☆40Updated 4 years ago
- Python port of MailSniper to exfiltrate emails via EWS endpoint☆88Updated 3 years ago
- This is a Poc for BIGIP iControl unauth RCE☆51Updated 4 years ago
- Impacket is a collection of Python classes for working with network protocols.☆39Updated 3 years ago
- Passwordless RDP Session Hijacking☆66Updated 3 years ago
- This script helps to identify CVE-2021-26855 ssrf Poc☆20Updated 4 years ago
- Generate image payloads in JS to bypass filters☆39Updated 4 years ago
- Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys☆20Updated 3 years ago