rtandr01d / zerologonLinks
Scan for and exploit the zerologon vulnerability.
☆11Updated 4 years ago
Alternatives and similar repositories for zerologon
Users that are interested in zerologon are comparing it to the libraries listed below
Sorting:
- Convert ldapdomaindump to Bloodhound☆80Updated last year
- A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.☆95Updated last year
- User enumeration and password spraying tool for testing Azure AD☆70Updated 3 years ago
- Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")☆57Updated last year
- Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers.☆47Updated 2 years ago
- A tool to abuse weak permissions of Active Directory Discretionary Access Control Lists (DACLs) and Access Control Entries (ACEs)☆58Updated last month
- The purpose of this repo is to share my research☆14Updated 4 months ago
- A script to automatically dump all URLs present in /server-status to a file locally.☆24Updated 6 months ago
- ☆52Updated 2 years ago
- OSEP - Offsec Expert Professional☆15Updated last year
- This repository presents a proof-of-concept of CVE-2023-22527☆12Updated last year
- Analyzes AdminSDHolder permissions & compares with default baseline or a previous run, to detect potential backdoor/excessive persistent …☆15Updated 4 months ago
- Apache commons text - CVE-2022-42889 Text4Shell proof of concept exploit.☆54Updated last year
- A script used to query the dehashed API and filter for more useful results☆17Updated 4 years ago
- Nmapurls parses Nmap xml reports from either piped input or command line arg and outputs a list of http(s) URL's to be used in an automat…☆42Updated 2 months ago
- Proof of Concept Exploit for CVE-2024-9465☆29Updated 10 months ago
- Microsoft Exchange password spray tool with proxy support.☆40Updated 4 years ago
- A script that greps composite key-like strings from a KeePassXC process dump, then uses a customized version of pykeepass library to unlo…☆32Updated 2 years ago
- Secretsdump C# version only supporting local (live) operation☆50Updated 4 months ago
- Exploits targeting vBulletin.☆76Updated 2 years ago
- Used to get NTLMv2 Hashes from SMB☆16Updated 10 months ago
- Simple Python script to sort nuclei scans by severity and URL☆29Updated 2 years ago
- Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler.☆55Updated last year
- Generate password spraying lists based on the pwdLastSet-attribute of users.☆56Updated last year
- ☆18Updated 3 years ago
- CVE-2023-20198 Exploit PoC☆56Updated last year
- RCE through a race condition in Apache Tomcat☆56Updated 8 months ago
- cve-2022-42889 Text4Shell CVE-2022-42889 affects Apache Commons Text versions 1.5 through 1.9. It has been patched as of Commons Text ver…☆39Updated 2 years ago
- Open-Source Phishing Toolkit☆19Updated 4 years ago
- A python script to force authentication using MS-RPRN RemoteFindFirstPrinterChangeNotificationEx function (opnum 65).☆26Updated 6 months ago