Skip to content
Avatar
🦋
🦋

Sponsors

@mxrch
Private Sponsor

Highlights

  • Pro
Block or Report

Block or report p0dalirius

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Add an optional note:
Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
p0dalirius/README.md


I'm a French Security Researcher and Microsoft MVP. I specialize in finding vulnerabilities in various environments, including Windows, Active Directory, and web applications. With a passion for tinkering with undefined behaviors in computers, I have published 90 open-source security tools so far, and there are many more to come! 🥳

If any of my tools have been helpful to you, please consider sponsoring my work. Sponsorship will support the costs of my projects, including server expenses, mainframe restoration, and research materials. You can support me through GitHub Sponsors https://github.com/sponsors/p0dalirius or through Patreon: https://www.patreon.com/podalirius

As part of my dedication to security, I actively report vulnerabilities I discover. To date, I have reported and responsibly disclosed 10 security vulnerabilities found in the wild. I have also received 6 CVEs (CVE-2020-16147, CVE-2020-16148, CVE-2021-43008, CVE-2022-26159, CVE-2022-29710, CVE-2022-30780), with 2 more awaiting release.


Summary of my tools

Active Directory tools

  • AccountShadowTakeover: A python script to automatically add a KeyCredentialLink to newly created users, by quickly connecting to them with default credentials.
  • Coercer: A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 9 methods.
  • DomainUsersToXLSX: Extract all users from an Active Directory domain to an Excel worksheet.
  • DumpSMBShare: A script to dump files and folders remotely from a Windows SMB share.
  • ExtractBitlockerKeys: A post-exploitation python script to automatically extract the bitlocker recovery keys from a domain.
  • FindUncommonShares: A Python tool allowing to quickly find uncommon shares in vast Windows Domains.
  • ldap2json: The ldap2json script allows you to extract the whole LDAP content of a Windows domain into a JSON file.
  • ldapconsole: The ldapconsole script allows you to perform custom LDAP requests to a Windows domain.
  • LDAPmonitor: Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration!
  • MSRPRN-Coerce: A python script to force authentification using MS-RPRN RemoteFindFirstPrinterChangeNotificationEx function (opnum 69).
  • pydsinternals: A Python native library containing necessary classes, functions and structures to interact with Windows Active Directory.
  • pyLAPS: Python setter/getter for property ms-Mcs-AdmPwd used by LAPS.
  • TargetAllDomainObjects: A python wrapper to run a command on against all users/computers/DCs of a Windows Domain.

Web exploitation tools

  • ApacheTomcatScanner: A python script to scan for Apache Tomcat server vulnerabilities.
  • Awesome-RCE-techniques: Awesome list of techniques to achieve Remote Code Execution on various apps!
  • crawlersuseragents: Python script to check if there is any differences in responses of an application when the request comes from a search engine's crawler.
  • http-fuzzing-scripts: A collection of http fuzzing python scripts to fuzz HTTP servers for bugs.
  • ipsourcebypass: This Python script can be used to bypass IP source restrictions using HTTP headers.
  • JoGet-plugin-webshell: A webshell plugin and interactive shell for pentesting JoGet application.
  • LimeSurvey-plugin-webshell: A webshell plugin and interactive shell for pentesting JoGet application.
  • LFIDump: A simple python script to dump remote files through a local file read or local file inclusion web vulnerability.
  • LootApacheServerStatus: A script to automatically dump all URLs present in /server-status to a file locally.
  • Moodle-webshell-plugin: A webshell plugin and interactive shell for pentesting a Moodle instance.
  • owabrute: Hydra wrapper for bruteforcing Microsoft Outlook Web Application.
  • RDWArecon: A python script to extract information from a Microsoft Remote Desktop Web Access (RDWA) application.
  • robotstester: This Python script can enumerate all URLs present in robots.txt files, and test whether they can be accessed or not.
  • robotsvalidator: The robotsvalidator script allows you to check if URLs are allowed or disallowed by a robots.txt file.
  • TimeBasedLoginUserEnum: A script to enumerate valid usernames based on the requests response times.
  • Tomcat-application-webshell: A webshell application and interactive shell for pentesting Apache Tomcat servers.
  • webapp-wordlists: This repository contains wordlists for each versions of common web applications and content management systems (CMS). Each version contains a wordlist of all the files directories for this version.

Vulnerability exploits

Windows

  • DownloadPDBSymbols: A Python script to download PDB files associated with a Portable Executable (PE).
  • hivetools: A collection of python scripts to work with Windows Hives.
  • msFlagsDecoder: Decode the values of common Windows properties such as userAccountControl and sAMAccountType.
  • OffensiveBatchScripts: Offensive batch scripts.
  • SortWindowsISOs: Extract the windows major and minor build numbers from an ISO file, and automatically sort the iso files.

Data & Researches

Other

  • Argon2Cracker: A multithreaded bruteforcer of argon2 hashes.
  • ctfd-parser: A python script to dump all the challenges locally of a CTFd-based Capture the Flag.
  • factorizator: A script to factorize integers with sagemath and factordb.
  • GetFortinetSerialNumber: A Python script to extract the serial number of a remote Fortinet device.
  • GithubBackupAllRepos: A Python script to backup all repos (public or private) of a user.
  • Hashes-Harvester: Automatically extracts NTLM hashes from Windows memory dumps.
  • ParseFortinetSerialNumber: A Python script to parse Fortinet products serial numbers, and detect the associated model and version.
  • python_packages_paths: This repository contains paths to python modules from inside python modules.
  • streamableDownloader: A simple python script to download videos hosted on streamable from their link.
  • wav2mmv: WAV to MMV converter. You can then use the MMV file in input of MSSTV to decode Slow Scan Television (SSTV) sound signals.
  • WifiListProbeRequests: Monitor 802.11 probe requests from a capture file or network sniffing!

Pinned

  1. Awesome list of step by step techniques to achieve Remote Code Execution on various apps!

    Dockerfile 1.7k 187

  2. Coercer Public

    A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

    Python 1.3k 151

  3. A python script to scan for Apache Tomcat server vulnerabilities.

    Python 667 84

  4. LDAPmonitor Public

    Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration!

    Python 574 53

  5. This repository contains wordlists for each versions of common web applications and content management systems (CMS). Each version contains a wordlist of all the files directories for this version.

    Python 433 103

  6. A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols.

    Python 414 50

1,254 contributions in the last year

Contribution Graph
Day of Week September October November December January February March April May June July August September
Sunday No contributions on Sunday, September 18, 2022 1 contribution on Sunday, September 25, 2022 1 contribution on Sunday, October 2, 2022 No contributions on Sunday, October 9, 2022 No contributions on Sunday, October 16, 2022 No contributions on Sunday, October 23, 2022 No contributions on Sunday, October 30, 2022 2 contributions on Sunday, November 6, 2022 No contributions on Sunday, November 13, 2022 No contributions on Sunday, November 20, 2022 1 contribution on Sunday, November 27, 2022 No contributions on Sunday, December 4, 2022 16 contributions on Sunday, December 11, 2022 No contributions on Sunday, December 18, 2022 6 contributions on Sunday, December 25, 2022 No contributions on Sunday, January 1, 2023 No contributions on Sunday, January 8, 2023 4 contributions on Sunday, January 15, 2023 No contributions on Sunday, January 22, 2023 3 contributions on Sunday, January 29, 2023 9 contributions on Sunday, February 5, 2023 10 contributions on Sunday, February 12, 2023 2 contributions on Sunday, February 19, 2023 No contributions on Sunday, February 26, 2023 No contributions on Sunday, March 5, 2023 No contributions on Sunday, March 12, 2023 No contributions on Sunday, March 19, 2023 No contributions on Sunday, March 26, 2023 No contributions on Sunday, April 2, 2023 6 contributions on Sunday, April 9, 2023 No contributions on Sunday, April 16, 2023 No contributions on Sunday, April 23, 2023 No contributions on Sunday, April 30, 2023 No contributions on Sunday, May 7, 2023 1 contribution on Sunday, May 14, 2023 10 contributions on Sunday, May 21, 2023 8 contributions on Sunday, May 28, 2023 3 contributions on Sunday, June 4, 2023 2 contributions on Sunday, June 11, 2023 No contributions on Sunday, June 18, 2023 5 contributions on Sunday, June 25, 2023 No contributions on Sunday, July 2, 2023 No contributions on Sunday, July 9, 2023 No contributions on Sunday, July 16, 2023 No contributions on Sunday, July 23, 2023 No contributions on Sunday, July 30, 2023 3 contributions on Sunday, August 6, 2023 4 contributions on Sunday, August 13, 2023 No contributions on Sunday, August 20, 2023 No contributions on Sunday, August 27, 2023 1 contribution on Sunday, September 3, 2023 No contributions on Sunday, September 10, 2023 No contributions on Sunday, September 17, 2023
Monday No contributions on Monday, September 19, 2022 6 contributions on Monday, September 26, 2022 No contributions on Monday, October 3, 2022 No contributions on Monday, October 10, 2022 No contributions on Monday, October 17, 2022 No contributions on Monday, October 24, 2022 No contributions on Monday, October 31, 2022 2 contributions on Monday, November 7, 2022 No contributions on Monday, November 14, 2022 No contributions on Monday, November 21, 2022 1 contribution on Monday, November 28, 2022 3 contributions on Monday, December 5, 2022 1 contribution on Monday, December 12, 2022 No contributions on Monday, December 19, 2022 3 contributions on Monday, December 26, 2022 No contributions on Monday, January 2, 2023 No contributions on Monday, January 9, 2023 No contributions on Monday, January 16, 2023 No contributions on Monday, January 23, 2023 1 contribution on Monday, January 30, 2023 2 contributions on Monday, February 6, 2023 11 contributions on Monday, February 13, 2023 5 contributions on Monday, February 20, 2023 1 contribution on Monday, February 27, 2023 No contributions on Monday, March 6, 2023 6 contributions on Monday, March 13, 2023 No contributions on Monday, March 20, 2023 1 contribution on Monday, March 27, 2023 2 contributions on Monday, April 3, 2023 No contributions on Monday, April 10, 2023 6 contributions on Monday, April 17, 2023 4 contributions on Monday, April 24, 2023 No contributions on Monday, May 1, 2023 No contributions on Monday, May 8, 2023 1 contribution on Monday, May 15, 2023 3 contributions on Monday, May 22, 2023 16 contributions on Monday, May 29, 2023 8 contributions on Monday, June 5, 2023 3 contributions on Monday, June 12, 2023 No contributions on Monday, June 19, 2023 12 contributions on Monday, June 26, 2023 4 contributions on Monday, July 3, 2023 1 contribution on Monday, July 10, 2023 No contributions on Monday, July 17, 2023 No contributions on Monday, July 24, 2023 6 contributions on Monday, July 31, 2023 31 contributions on Monday, August 7, 2023 No contributions on Monday, August 14, 2023 No contributions on Monday, August 21, 2023 No contributions on Monday, August 28, 2023 1 contribution on Monday, September 4, 2023 1 contribution on Monday, September 11, 2023 No contributions on Monday, September 18, 2023
Tuesday 1 contribution on Tuesday, September 20, 2022 1 contribution on Tuesday, September 27, 2022 No contributions on Tuesday, October 4, 2022 2 contributions on Tuesday, October 11, 2022 No contributions on Tuesday, October 18, 2022 No contributions on Tuesday, October 25, 2022 No contributions on Tuesday, November 1, 2022 No contributions on Tuesday, November 8, 2022 1 contribution on Tuesday, November 15, 2022 No contributions on Tuesday, November 22, 2022 3 contributions on Tuesday, November 29, 2022 No contributions on Tuesday, December 6, 2022 10 contributions on Tuesday, December 13, 2022 6 contributions on Tuesday, December 20, 2022 3 contributions on Tuesday, December 27, 2022 No contributions on Tuesday, January 3, 2023 No contributions on Tuesday, January 10, 2023 4 contributions on Tuesday, January 17, 2023 1 contribution on Tuesday, January 24, 2023 No contributions on Tuesday, January 31, 2023 4 contributions on Tuesday, February 7, 2023 9 contributions on Tuesday, February 14, 2023 1 contribution on Tuesday, February 21, 2023 No contributions on Tuesday, February 28, 2023 No contributions on Tuesday, March 7, 2023 No contributions on Tuesday, March 14, 2023 No contributions on Tuesday, March 21, 2023 6 contributions on Tuesday, March 28, 2023 No contributions on Tuesday, April 4, 2023 2 contributions on Tuesday, April 11, 2023 1 contribution on Tuesday, April 18, 2023 2 contributions on Tuesday, April 25, 2023 1 contribution on Tuesday, May 2, 2023 13 contributions on Tuesday, May 9, 2023 2 contributions on Tuesday, May 16, 2023 3 contributions on Tuesday, May 23, 2023 99 contributions on Tuesday, May 30, 2023 4 contributions on Tuesday, June 6, 2023 2 contributions on Tuesday, June 13, 2023 3 contributions on Tuesday, June 20, 2023 4 contributions on Tuesday, June 27, 2023 No contributions on Tuesday, July 4, 2023 2 contributions on Tuesday, July 11, 2023 No contributions on Tuesday, July 18, 2023 No contributions on Tuesday, July 25, 2023 1 contribution on Tuesday, August 1, 2023 2 contributions on Tuesday, August 8, 2023 1 contribution on Tuesday, August 15, 2023 No contributions on Tuesday, August 22, 2023 No contributions on Tuesday, August 29, 2023 6 contributions on Tuesday, September 5, 2023 No contributions on Tuesday, September 12, 2023 9 contributions on Tuesday, September 19, 2023
Wednesday 1 contribution on Wednesday, September 21, 2022 No contributions on Wednesday, September 28, 2022 7 contributions on Wednesday, October 5, 2022 No contributions on Wednesday, October 12, 2022 1 contribution on Wednesday, October 19, 2022 1 contribution on Wednesday, October 26, 2022 No contributions on Wednesday, November 2, 2022 1 contribution on Wednesday, November 9, 2022 No contributions on Wednesday, November 16, 2022 3 contributions on Wednesday, November 23, 2022 6 contributions on Wednesday, November 30, 2022 No contributions on Wednesday, December 7, 2022 16 contributions on Wednesday, December 14, 2022 2 contributions on Wednesday, December 21, 2022 3 contributions on Wednesday, December 28, 2022 No contributions on Wednesday, January 4, 2023 No contributions on Wednesday, January 11, 2023 2 contributions on Wednesday, January 18, 2023 1 contribution on Wednesday, January 25, 2023 2 contributions on Wednesday, February 1, 2023 No contributions on Wednesday, February 8, 2023 2 contributions on Wednesday, February 15, 2023 22 contributions on Wednesday, February 22, 2023 6 contributions on Wednesday, March 1, 2023 No contributions on Wednesday, March 8, 2023 No contributions on Wednesday, March 15, 2023 1 contribution on Wednesday, March 22, 2023 4 contributions on Wednesday, March 29, 2023 No contributions on Wednesday, April 5, 2023 No contributions on Wednesday, April 12, 2023 1 contribution on Wednesday, April 19, 2023 32 contributions on Wednesday, April 26, 2023 1 contribution on Wednesday, May 3, 2023 11 contributions on Wednesday, May 10, 2023 2 contributions on Wednesday, May 17, 2023 5 contributions on Wednesday, May 24, 2023 No contributions on Wednesday, May 31, 2023 4 contributions on Wednesday, June 7, 2023 2 contributions on Wednesday, June 14, 2023 3 contributions on Wednesday, June 21, 2023 2 contributions on Wednesday, June 28, 2023 3 contributions on Wednesday, July 5, 2023 4 contributions on Wednesday, July 12, 2023 No contributions on Wednesday, July 19, 2023 9 contributions on Wednesday, July 26, 2023 3 contributions on Wednesday, August 2, 2023 5 contributions on Wednesday, August 9, 2023 1 contribution on Wednesday, August 16, 2023 1 contribution on Wednesday, August 23, 2023 No contributions on Wednesday, August 30, 2023 2 contributions on Wednesday, September 6, 2023 8 contributions on Wednesday, September 13, 2023 14 contributions on Wednesday, September 20, 2023
Thursday 1 contribution on Thursday, September 22, 2022 No contributions on Thursday, September 29, 2022 3 contributions on Thursday, October 6, 2022 No contributions on Thursday, October 13, 2022 2 contributions on Thursday, October 20, 2022 No contributions on Thursday, October 27, 2022 3 contributions on Thursday, November 3, 2022 No contributions on Thursday, November 10, 2022 No contributions on Thursday, November 17, 2022 1 contribution on Thursday, November 24, 2022 3 contributions on Thursday, December 1, 2022 No contributions on Thursday, December 8, 2022 7 contributions on Thursday, December 15, 2022 No contributions on Thursday, December 22, 2022 No contributions on Thursday, December 29, 2022 No contributions on Thursday, January 5, 2023 3 contributions on Thursday, January 12, 2023 1 contribution on Thursday, January 19, 2023 29 contributions on Thursday, January 26, 2023 4 contributions on Thursday, February 2, 2023 2 contributions on Thursday, February 9, 2023 No contributions on Thursday, February 16, 2023 No contributions on Thursday, February 23, 2023 1 contribution on Thursday, March 2, 2023 1 contribution on Thursday, March 9, 2023 1 contribution on Thursday, March 16, 2023 1 contribution on Thursday, March 23, 2023 9 contributions on Thursday, March 30, 2023 No contributions on Thursday, April 6, 2023 2 contributions on Thursday, April 13, 2023 No contributions on Thursday, April 20, 2023 10 contributions on Thursday, April 27, 2023 No contributions on Thursday, May 4, 2023 11 contributions on Thursday, May 11, 2023 No contributions on Thursday, May 18, 2023 1 contribution on Thursday, May 25, 2023 No contributions on Thursday, June 1, 2023 No contributions on Thursday, June 8, 2023 3 contributions on Thursday, June 15, 2023 1 contribution on Thursday, June 22, 2023 5 contributions on Thursday, June 29, 2023 1 contribution on Thursday, July 6, 2023 1 contribution on Thursday, July 13, 2023 No contributions on Thursday, July 20, 2023 3 contributions on Thursday, July 27, 2023 No contributions on Thursday, August 3, 2023 No contributions on Thursday, August 10, 2023 3 contributions on Thursday, August 17, 2023 3 contributions on Thursday, August 24, 2023 No contributions on Thursday, August 31, 2023 4 contributions on Thursday, September 7, 2023 3 contributions on Thursday, September 14, 2023
Friday 2 contributions on Friday, September 23, 2022 2 contributions on Friday, September 30, 2022 1 contribution on Friday, October 7, 2022 No contributions on Friday, October 14, 2022 No contributions on Friday, October 21, 2022 No contributions on Friday, October 28, 2022 No contributions on Friday, November 4, 2022 No contributions on Friday, November 11, 2022 1 contribution on Friday, November 18, 2022 No contributions on Friday, November 25, 2022 No contributions on Friday, December 2, 2022 No contributions on Friday, December 9, 2022 1 contribution on Friday, December 16, 2022 No contributions on Friday, December 23, 2022 No contributions on Friday, December 30, 2022 2 contributions on Friday, January 6, 2023 No contributions on Friday, January 13, 2023 No contributions on Friday, January 20, 2023 2 contributions on Friday, January 27, 2023 3 contributions on Friday, February 3, 2023 No contributions on Friday, February 10, 2023 No contributions on Friday, February 17, 2023 No contributions on Friday, February 24, 2023 15 contributions on Friday, March 3, 2023 No contributions on Friday, March 10, 2023 No contributions on Friday, March 17, 2023 2 contributions on Friday, March 24, 2023 10 contributions on Friday, March 31, 2023 No contributions on Friday, April 7, 2023 3 contributions on Friday, April 14, 2023 1 contribution on Friday, April 21, 2023 7 contributions on Friday, April 28, 2023 1 contribution on Friday, May 5, 2023 2 contributions on Friday, May 12, 2023 No contributions on Friday, May 19, 2023 No contributions on Friday, May 26, 2023 No contributions on Friday, June 2, 2023 No contributions on Friday, June 9, 2023 3 contributions on Friday, June 16, 2023 2 contributions on Friday, June 23, 2023 No contributions on Friday, June 30, 2023 No contributions on Friday, July 7, 2023 No contributions on Friday, July 14, 2023 2 contributions on Friday, July 21, 2023 No contributions on Friday, July 28, 2023 No contributions on Friday, August 4, 2023 No contributions on Friday, August 11, 2023 No contributions on Friday, August 18, 2023 2 contributions on Friday, August 25, 2023 4 contributions on Friday, September 1, 2023 No contributions on Friday, September 8, 2023 No contributions on Friday, September 15, 2023
Saturday 20 contributions on Saturday, September 24, 2022 No contributions on Saturday, October 1, 2022 No contributions on Saturday, October 8, 2022 No contributions on Saturday, October 15, 2022 No contributions on Saturday, October 22, 2022 No contributions on Saturday, October 29, 2022 No contributions on Saturday, November 5, 2022 No contributions on Saturday, November 12, 2022 No contributions on Saturday, November 19, 2022 No contributions on Saturday, November 26, 2022 No contributions on Saturday, December 3, 2022 No contributions on Saturday, December 10, 2022 299 contributions on Saturday, December 17, 2022 1 contribution on Saturday, December 24, 2022 No contributions on Saturday, December 31, 2022 No contributions on Saturday, January 7, 2023 No contributions on Saturday, January 14, 2023 2 contributions on Saturday, January 21, 2023 15 contributions on Saturday, January 28, 2023 No contributions on Saturday, February 4, 2023 2 contributions on Saturday, February 11, 2023 No contributions on Saturday, February 18, 2023 No contributions on Saturday, February 25, 2023 No contributions on Saturday, March 4, 2023 No contributions on Saturday, March 11, 2023 3 contributions on Saturday, March 18, 2023 4 contributions on Saturday, March 25, 2023 No contributions on Saturday, April 1, 2023 No contributions on Saturday, April 8, 2023 5 contributions on Saturday, April 15, 2023 No contributions on Saturday, April 22, 2023 31 contributions on Saturday, April 29, 2023 No contributions on Saturday, May 6, 2023 No contributions on Saturday, May 13, 2023 No contributions on Saturday, May 20, 2023 No contributions on Saturday, May 27, 2023 3 contributions on Saturday, June 3, 2023 1 contribution on Saturday, June 10, 2023 1 contribution on Saturday, June 17, 2023 9 contributions on Saturday, June 24, 2023 No contributions on Saturday, July 1, 2023 No contributions on Saturday, July 8, 2023 No contributions on Saturday, July 15, 2023 1 contribution on Saturday, July 22, 2023 No contributions on Saturday, July 29, 2023 18 contributions on Saturday, August 5, 2023 No contributions on Saturday, August 12, 2023 No contributions on Saturday, August 19, 2023 No contributions on Saturday, August 26, 2023 5 contributions on Saturday, September 2, 2023 No contributions on Saturday, September 9, 2023 No contributions on Saturday, September 16, 2023
Activity overview

Contribution activity

September 2023

Created 1 repository
Opened 1 pull request in 1 repository
p0dalirius/RDWArecon 1 merged
Reviewed 1 pull request in 1 repository
p0dalirius/Coercer 1 pull request

Created an issue in p0dalirius/RDWArecon that received 1 comment

22 contributions in private repositories Sep 1 – Sep 20

Seeing something unexpected? Take a look at the GitHub profile guide.