p0dalirius / AccountShadowTakeover
A python script to automatically add a KeyCredentialLink to newly created users, by quickly connecting to them with default credentials.
☆22Updated last year
Alternatives and similar repositories for AccountShadowTakeover:
Users that are interested in AccountShadowTakeover are comparing it to the libraries listed below
- A collection of http fuzzing python scripts to fuzz HTTP servers for bugs.☆15Updated last year
- A Python script to find tenant id an region from a list of domain names.☆14Updated last month
- A python script to force authentication using MS-RPRN RemoteFindFirstPrinterChangeNotificationEx function (opnum 65).☆21Updated last month
- A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.☆12Updated 2 years ago
- Multithreaded spraying of a password on all accounts of a domain.☆19Updated last month
- A webshell plugin and interactive shell for pentesting a LimeSurvey application.☆17Updated 4 months ago
- This repository presents a proof-of-concept of CVE-2023-22527☆12Updated last year
- Decode the values of common Windows properties such as userAccountControl and sAMAccountType.☆21Updated last year
- A python wrapper to run a command on against all users/computers/DCs of a Windows Domain☆28Updated 2 years ago
- Python script to check if there is any differences in responses of an application when the request comes from a search engine's crawler.☆21Updated last year
- CVE-2022-30780 - lighttpd remote denial of service☆16Updated last year
- Command line tool to fetch, decode and brute-force CodeIgniter session cookies by guessing and bruteforcing secret keys.☆12Updated last month
- A straightforward tool for exploiting SMTP Smuggling vulnerabilities.☆14Updated 8 months ago
- A script to automatically dump all URLs present in /server-status to a file locally.☆23Updated last month
- List accounts with Service Principal Names (SPN) not linked to active dns records in an Active Directory Domain.☆17Updated last month
- MailMasta wordpress plugin Local File Inclusion vulnerability (CVE-2016-10956)☆16Updated 2 years ago
- A Python native library containing lots of useful functions to write efficient scripts to hack stuff.☆33Updated last month
- A tool to extract and dump files of mercurial SCM exposed on a web server.☆10Updated last month
- Proof of Concept Exploit for CVE-2024-9465☆29Updated 5 months ago
- Extract the windows major and minor build numbers from an ISO file, and automatically sort the iso files.☆14Updated 5 months ago
- A script to factorize integers with sagemath and factordb.☆11Updated last month
- Automatically extracts NT and LM hashes from Windows memory dumps based on volatility.☆24Updated last year
- Tomcat backdoor based on CS blog☆27Updated last year
- A python script to check if URLs are allowed or disallowed by a robots.txt file.☆21Updated last month
- Tool to aid in dumping LSASS process remotely☆38Updated 7 months ago
- A python library to interact with Pwndoc instances for pentest reports generation☆16Updated last month
- Tools for Attacking Pleasant Password Server☆21Updated last year
- Extract all users from an Active Directory domain to an Excel worksheet.☆32Updated last month
- A webshell plugin and interactive shell for pentesting JoGet application.☆12Updated 2 years ago
- A script that greps composite key-like strings from a KeePassXC process dump, then uses a customized version of pykeepass library to unlo…☆32Updated 2 years ago