blazeinfosec / ssrf-ntlm
Proof of concept written in Python to show that in some situations a SSRF vulnerability can be used to steal NTLMv1/v2 hashes.
☆57Updated 7 years ago
Alternatives and similar repositories for ssrf-ntlm:
Users that are interested in ssrf-ntlm are comparing it to the libraries listed below
- A proof of concept that demonstrates asynchronous scanning for Java deserialization bugs☆54Updated 7 years ago
- All about CVE-2018-14667; From what it is to how to successfully exploit it.☆50Updated 6 years ago
- Learn how to get a reverse shell from JIRA application server☆24Updated 6 years ago
- ☆34Updated 5 years ago
- Cobaltstrike Aggressor Scripts☆28Updated 7 years ago
- Python api for usage with cobalt strike's External C2 specification☆61Updated 6 years ago
- XSS payloads for edge cases☆34Updated 6 years ago
- CVE-2017-10271 WEBLOGIC RCE (TESTED)☆38Updated 7 years ago
- sploit☆68Updated 5 years ago
- Use Waitfor.exe to maintain persistence☆54Updated 3 years ago
- This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.4☆36Updated 5 years ago
- ☆44Updated 4 years ago
- A tool to analyse JMX API security level.☆43Updated 10 years ago
- Custom THP Dropper☆27Updated 6 years ago
- CORS checking☆35Updated 6 years ago
- Use to perform Microsoft exchange account brute-force.☆73Updated 3 years ago
- Burp Suite Attack Selector Plugin☆61Updated 7 years ago
- PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM☆53Updated 6 years ago
- A simple scanner to find and brute force tomcat manager logins☆28Updated 5 years ago
- Kerberos accounts enumeration taking advantage of AS-REQ☆43Updated 6 years ago
- guest→system(UAC手动提权)☆74Updated 4 years ago
- ☆63Updated 5 years ago
- ☆29Updated 6 years ago
- ☆52Updated 5 years ago
- Use powershell to test Office-based persistence methods☆75Updated 3 years ago
- A weaponized version of CVE-2018-9206☆62Updated 6 years ago
- Another plugin for CRLF vulnerability detection☆26Updated 8 years ago
- with metasploit☆63Updated 4 years ago
- ☆32Updated 4 years ago
- A relatively flexible tool to parse mimikatz output☆35Updated 8 years ago