#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

This project aims at re-analyzing and PoC about CVE-2023-33733. Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a…

CVE-2024-21413 Setup for CW

Roundcube 1.0.0 <= 1.2.2 Remote Code Execution exploit and vulnerable container

Security documentation and lab companion for the polkit pkexec local privilege escalation, with a TryHackMe room for hands-on exploitation practice.

XZ Utils CVE-2024-3094 POC for Kubernetes

CVE-2023-50164 An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a…

Reproduction environment for CVE-2023-4357 Chrome XXE vulnerability with SVG-based file access bypass exploit and step-by-step setup instructions.

Making a lab and testing the CVE-2024-3116, a Remote Code Execution in pgadmin <=8.4

An Ansible Role that installs the xz backdoor (CVE-2024-3094) on a Debian host and optionally installs the xzbot tool.

Educational proof-of-concept replicating CVE-2021-38297, a Go WASM buffer overflow leading to stored XSS. Includes vulnerable app setup, exploit…

A convenient and time-saving auto script of building environment and exploit it.

This is a container environment running CVE-2024-3094 sshd backdoor instance, working with https://github.com/amlweems/xzbot project. IT IS NOT…

LAB: TẤN CÔNG HỆ ĐIỀU HÀNH WINDOWS DỰA VÀO LỖ HỔNG GIAO THỨC SMB.

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

More specific : Dirty COW (CVE-2016-5195)

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

WVCTF or WebVulnCTF is a gamified web platform which promotes training in pentesting and web application development security in an entertaining way.…

Exploit for CVE-2023-22518 in Atlassian Confluence. Provides a detailed walkthrough of the vulnerability, including environment setup, root cause…