p0dalirius / AccountShadowTakeoverLinks
A python script to automatically add a KeyCredentialLink to newly created users, by quickly connecting to them with default credentials.
☆22Updated last year
Alternatives and similar repositories for AccountShadowTakeover
Users that are interested in AccountShadowTakeover are comparing it to the libraries listed below
Sorting:
- A script to factorize integers with sagemath and factordb.☆12Updated 7 months ago
- A python wrapper to run a command on against all users/computers/DCs of a Windows Domain☆28Updated 2 years ago
- A webshell plugin and interactive shell for pentesting a LimeSurvey application.☆21Updated 10 months ago
- Command line tool to fetch, decode and brute-force CodeIgniter session cookies by guessing and bruteforcing secret keys.☆14Updated 7 months ago
- Multithreaded spraying of a password on all accounts of a domain.☆23Updated 7 months ago
- A webshell plugin and interactive shell for pentesting JoGet application.☆13Updated 3 years ago
- A collection of http fuzzing python scripts to fuzz HTTP servers for bugs.☆15Updated last year
- A python script to force authentication using MS-RPRN RemoteFindFirstPrinterChangeNotificationEx function (opnum 65).☆26Updated 7 months ago
- Pwndoc local file inclusion to remote code execution of Node.js code on the server☆46Updated 7 months ago
- A tool to extract and dump files of mercurial SCM exposed on a web server.☆13Updated 7 months ago
- A script to automatically dump all URLs present in /server-status to a file locally.☆24Updated 7 months ago
- A Python script to find tenant id an region from a list of domain names.☆15Updated 7 months ago
- A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.☆13Updated 3 years ago
- A script to enumerate valid usernames based on the requests response times.☆20Updated 3 years ago
- A python script to check if URLs are allowed or disallowed by a robots.txt file.☆22Updated 7 months ago
- Python script to check if there is any differences in responses of an application when the request comes from a search engine's crawler.☆22Updated last year
- The ldapconsole script allows you to perform custom LDAP requests to a Windows domain.☆64Updated 7 months ago
- This repository presents a proof-of-concept of CVE-2023-22527☆12Updated last year
- A Python script to parse Fortinet products serial numbers, and detect the associated model and revision.☆18Updated last year
- Automatically extracts NT and LM hashes from Windows memory dumps based on volatility.☆26Updated last year
- A Python native library containing lots of useful functions to write efficient scripts to hack stuff.☆38Updated this week
- Decode the values of common Windows properties such as userAccountControl and sAMAccountType.☆23Updated last year
- MailMasta wordpress plugin Local File Inclusion vulnerability (CVE-2016-10956)☆19Updated 3 years ago
- Extract all users from an Active Directory domain to an Excel worksheet.☆32Updated 7 months ago
- A Python script to extract the list of users of a GiTea instance, unauthenticated or authenticated.☆15Updated 7 months ago
- CVE-2022-30780 - lighttpd remote denial of service☆17Updated last year
- A python tool to generate an Excel file linking the list of cracked accounts and their LDAP attributes.☆10Updated 7 months ago
- Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler.☆55Updated last year
- Scan for and exploit the zerologon vulnerability.☆10Updated 5 years ago
- A webshell plugin and interactive shell for pentesting a Moodle instance.☆36Updated 7 months ago