-
Notifications
You must be signed in to change notification settings - Fork 132
Home
knavesec edited this page Mar 22, 2021
·
5 revisions
CredMaster allows you to launch a password spray via Amazon AWS passthrough proxies, shifting the requesting IP address for every authentication attempt. This dynamically creates FireProx APIs for evasive password sprays, and spoofs tracking headers to avoid detection.
This was released in this blog post: https://whynotsecurity.com/blog/credmaster
- Fully supports all AWS Regions
- Automatically generates APIs for proxy pass-through
- Spoofs API tracking numbers, forwarded-for IPs, and other proxy tracking headers
- Multi-threaded processing
- Password delay counters & configuration for lockout policy evasion
- Easily add new plugins
- Fully anonymous