Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
Exploits — Exploits von 1N3 @CrowdShield @xer0dayz @XeroSecurity | Kitploit
Tools/GitHubGitHub/1n3/exploits
Exploit-FrameworksSchwachstellenanalyseExploitationWebanwendungs-ExploitationCTFPenetrationstests
GitHub1n3/exploits

Exploits

Exploits von 1N3 @CrowdShield @xer0dayz @XeroSecurity

Repository anzeigen
208101vor 4 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
Webseite

Eine Sammlung von Exploits, entwickelt von @xer0dayz @Sn1perSecurity https://sn1persecurity.com

  • Vulnserver.exe GMON SEH Overflow Exploit
  • FreeFloat FTP Server HOST Buffer Overflow (ASLR Bypass)
  • CoolPlayer+ Portable 2.19.6 Stack Overflow (ASLR Bypass)
  • HTTPoxy Exploit/PoC Scanner
  • Ability FTP 2.34 Buffer Overflow Exploit
  • Aruba AP-205 Buffer Overflow Denial of Service PoC
  • Brainpan1 CTF Buffer Overflow Exploit
  • CesarFTP 0.99g Buffer Overflow Exploit
  • Apache 2.2.x Range Header Denial of Service Exploit
  • GHOST Glibc Gethostbyname Buffer Overflow Exploit
  • PHP Serialization Injection Remote Code Execution Exploit
  • CrikeyConCTF Koala Gallery Exploit
  • Webmin 1.920 Unauthenticated RCE Metasploit Exploit

Bug-Bounty-Profile

  • https://bugcrowd.com/1N3
  • https://hackerone.com/1N3

Öffentliche Exploits

  • https://packetstormsecurity.com/files/author/1N3/
  • https://www.exploit-db.com/?author=7787
  • https://vulners.com/search?query=1N3

Blogs

  • https://sn1persecurity.com/wordpress/blog/
  • https://crowdshield.com/blog.php
  • https://treadstonesecurity.blogspot.ca

Soziale Medien

  • https://twitter.com/xer0dayz
  • https://twitter.com/sn1persecurity
  • https://twitter.com/crowdshield
  • https://youtube.com/crowdshield
  • https://youtube.com/sn1persecurity

Websites

  • https://sn1persecurity.com
  • https://crowdshield.com

Öffentliche Exploits/PoCs/CVEs/Bug-Bounties/CTFs

2018:

  • Vorgestellt im Hackin9 Magazine – Ausgabe Open Source Hacking Tools (https://hakin9.org/download/open-source-hacking-tools/) 8/2018
  • Jetty 6.1.6 Cross-Site-Scripting (XSS) (https://seclists.org/fulldisclosure/2018/Aug/15) (Full Disclosure) 8/2018
  • Aufgeführt in der HoF des DoD Defense Travel System 6/2018
  • Vorqualifiziert für die BugCrowd-2018-MVP-Research-Liste (https://www.bugcrowd.com/bugcrowd-mvps-april-edition/) 4/2018
  • CVE-2018-8917 Synology-SA-18:14 – Reflektiertes XSS in DSM 6.1.5-15254 (https://www.synology.com/en-us/security/advisory/Synology_SA_18_14) 3/2018
  • CVE-2018-6545 Ipswitch MoveIt v8.1 Gespeichertes Cross-Site-Scripting (XSS) (https://www.exploit-db.com/exploits/43947) 2/2018
  • Mehrere Cross-Site-Scripting (XSS)-Schwachstellen in Illustra-IP-Kameras (600-Dollar-Bounty) 2/2018
  • Verzeichnis-Traversal-Schwachstelle in Illustra-IP-Kameras (800-Dollar-Bounty) 2/2018
  • Schwachstelle für Remote-Befehlsausführung in Illustra-IP-Kameras (900-Dollar-Bounty) 2/2018
  • Aufgeführt auf der BugCrowd-2017-MVP-Forscherliste (https://www.bugcrowd.com/today-we-recognize-our-2017-mvp-researchers/) 1/2018

2017:

  • Erhielt die Offensive Security Certified Expert (OSCE)-Zertifizierung 12/2017
  • Mehrere Cross-Site-Request-Forgery (CSRF)-Schwachstellen in der WEMO-HomeKit-Bridge (3.000-Dollar-Bounty) 9/2017
  • Gespeicherte Cross-Site-Scripting (XSS)-Schwachstelle in der WEMO-HomeKit-Bridge (500-Dollar-Bounty) 9/2017
  • Systemische gespeicherte XSS-Schwachstelle in der WEMO-HomeKit-Android-App (1.500-Dollar-Bounty) 9/2017
  • Systemische Local File Inclusion in der DEMO-HomeKit-Android-App (3.000-Dollar-Bounty) 9/2017
  • Erreichte den 7. Platz bei der ToorConCTF CTF 8/2017
  • Gespeichertes XSS in der ModSecurity-App für Splunk (Full Disclosure) 8/2017
  • Verzeichnis-Traversal in der PSPDFKit/Atlassian Jira Cloud Android-App (Bug Bounty) 7/2017
  • Erhielt die Android Security for Penetration Testers (ASFP)-Zertifizierung von SecurityTube 5/2017
  • Hielt einen Vortrag bei ISSA/OWASP Phoenix vor über 90 Teilnehmern mit dem Titel „Man In The Browser Advanced Client Side Exploitation“ (https://www.slideshare.net/1N3/man-in-the-browser-advanced-client-side-exploitation-using-beef) 4/2017
  • PSV-2017-0227: Cross-Site-Tracing-Schwachstelle in NETGEAR Arlo CVE 2/2017
  • Verzeichnis-Traversal + mehrere CSRF + mehrere gespeicherte und reflektierte XSS in NETGEAR-M4300-8X8F-Switches (3.000+-Dollar-Bounty) 3/2017
  • Erhielt die HackerOne-Challenge-Münze des Verteidigungsministeriums für das Hack-The-Army-Bug-Bounty-Programm 2/2017
  • Aufgeführt auf der BugCrowd-2016-MVP-Liste 1/2017

2016:

  • Erreichte den 3. Platz beim Operation-Code-CTF von BugCrowd 9/2016
    1. Platz beim @DEFCON CMD+CTRL CTF 8/2016
  • HTTPoxy Exploit Scanner Exploit/PoC 7/2016
  • CVE-2016-1034 Zabbix SQL Injection 0day (www.cvedetails.com/cve/CVE-2016-10134/) 7/2016
  • CVE-2016-4401 Unauthentifizierter Datenbank-Zugangsdaten-Leak in Aruba ClearPass (1.500-Dollar-Bounty) (https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-010.txt) 6/2016
  • Teilte sich den 2. Platz beim BugCrowd Operation Code CTF 6/2016
  • Schaffte es auf die Top-10-Forscherliste bei BugCrowd 6/2016
  • Erreichte den 2. Platz beim CactusCon 2016 RootTheBox CTF 5/2016
  • Rangierte auf Platz 19 des weltweiten BugCrowd-Leaderboards (Bug Bounty) 5/2016
  • Charts 4 PHP 1.2.3 Cross Site Scripting (Full Disclosure) (https://packetstormsecurity.com/files/135666/Charts-4-PHP-1.2.3-Cross-Site-Scripting.html) 2/2016
  • Open Web Analytics 1.5.7 Cross Site Scripting (Full Disclosure) (https://packetstormsecurity.com/files/135948/Open-Web-Analytics-1.5.7-Cross-Site-Scripting.html) 2/2016
  • WordPress All In One SEO Pack 2.2.2 Cross Site Scripting (Full Disclosure) 2/2016
  • PSV-2016-0127: Verzeichnis-Traversal in NETGEAR-R7800-Routern (0day) (https://kb.netgear.com/000053136/Security-Advisory-for-Arbitrary-File-Read-on-Some-Routers-and-Gateways-PSV-2016-0127) 1/2016
  • PSV-2016-0124: Klartext-Übermittlung von Passwörtern in NETGEAR-R7800-Routern (0day) (https://kb.netgear.com/000055105/Security-Advisory-for-Security-Misconfiguration-on-Some-Routers-and-Extenders-PSV-2016-0124) 1/2016
  • PSV-2016-0116: Denial of Service (DoS) in NETGEAR-R7800-Routern (0day) 1/2016
  • PSV-2016-0136: Uneingeschränkter beliebiger Datei-Upload in NETGEAR-R7800-Routern (0day) (https://kb.netgear.com/000049063/Security-Advisory-for-Security-Misconfiguration-Vulnerability-on-R7800-Routers-PSV-2017-0136) 1/2016

2015:

  • Schaffte es auf die Top-10-Forscherliste bei BugCrowd 11/2015
  • Wordpress XMLRPC System Multicall Brute Force Exploit (0day) Exploit/PoC 10/2015
  • Aruba AP-205 Remote-Befehlsinjektions-Schwachstelle (750-Dollar-Bounty) (https://www.youtube.com/watch?v=TZqDkN1NQf4) 10/2015
  • Apache Range Header Denial of Service Exploit (CVE-2011-3192) Exploit/PoC 8/2015
  • Aufgeführt in der Bug-Bounty-Hall-of-Fame von AT&T (Bug Bounty) (https://bugbounty.att.com/hof.php) 8/2015
  • Gewann die Practical-Web-CTF-#2-Challenge des InfoSec Institute (https://resources.infosecinstitute.com/ctf-2-practical-web-hacking-winners/#gref) 8/2015
  • HP Photosmart 7520 Drucker – Gespeichertes Cross Site Scripting (0day) Exploit/CVE 7/2015
  • Supermicro IPMI/BMC Cleartext Password Scanner Exploit/PoC 3/2015
  • WebFOCUS 533 Server XSS- und Verzeichnis-Traversal-Schwachstellen (0day) Exploit/CVE 2/2015
  • Imgur Server-Side-Request-Forgery (SSRF) (1.600-Dollar-Bounty) (https://hackerone.com/reports/91816) 1/2015
  • CVE-2015-0235 GHOST glibc gethostbyname Buffer Overflow Exploit (https://www.exploit-db.com/exploits/35951) 1/2015
  • Hak5 Wifi PinnappleV Remote Code Execution Exploit/CVE 1/2015
  • Hak5 Wifi PinnappleV SSLSplit Cross Site Scripting Exploit/CVE 1/2015

2014:

  • Lyris ListManagerWeb 8.95a Cross Site Scripting (Full Disclosure) (https://packetstormsecurity.com/files/127672/Lyris-ListManagerWeb-8.95a-Cross-Site-Scripting.html) 7/2014
  • MyConnection Server (MCS) 9.7i Cross Site Scripting (Full Disclosure) (https://0day.today/exploit/description/22526) 7/2014
  • AlogoSec FireFlow 6.3 Cross Site Scripting (Full Disclosure) (https://packetstormsecurity.com/files/127001/AlogoSec-FireFlow-6.3-Cross-Site-Scripting.html) 7/2014
  • Erhielt die Offensive Security Certified Professional (OSCP)-Zertifizierung 2/2014
Tool herunterladen
  • PSV-2016-0114: Verzeichnis-Traversal in NETGEAR-R7800-Routern (0day) (https://kb.netgear.com/000053135/Security-Advisory-for-Arbitrary-File-Read-on-Some-Routers-and-Gateways-PSV-2016-0114) 1/2016
  • PSV-2016-0113: Denial of Service (DoS) in NETGEAR-R7800-Routern (0day) 1/2016
  • PSV-2016-0131: Server-Side-Request-Forgery in NETGEAR-R7800-Routern (0day) (https://kb.netgear.com/000053137/Security-Advisory-for-Security-Misconfiguration-on-Some-Routers-and-Gateways-PSV-2016-0131) 1/2016