Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/epsilonpoint88-glitch/epsilonpoint-
Privilege EscalationVulnerability ScannersPersistence MechanismsExploitationWeb Application ExploitationPost-ExploitationPenetration TestingCommand and ControlRed TeamingPayload Development
GitHubepsilonpoint88-glitch/epsilonpoint-

EpSiLoNPoInT-

Modular exploit framework targeting CVE-2026-23550 in WordPress, featuring mass exploitation, obfuscation, post-exploitation, and Docker-based C2 infrastructure.

View Repository
11147 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

#!/usr/bin/env python3 """ TSAR-EXEC v7.1 + EpSiLoNPoInTFuCK v5.1 - Complete README.md Ready to Copy-Paste CVE-2026-23550 | Massive Modular DS Auth Bypass Exploitation Framework Author: EpSiLoNPoInT | Version: 7.1-GOD | Android 24h Coding | 08/02/2026 """

=============================================================================

TSAR-EXEC v7.1 - MODULAR-DS APT FRAMEWORK CVE-2026-23550 (CVSS 10.0)

=============================================================================

""" Industrial exploitation framework designed for threat intel and authorized red teaming. Exploits CVE-2026-23550 enabling privilege escalation via modular_ds_upload RCE. Coded entirely on an Android phone in 24h. Nation-state ready architecture.

✅ 40K+ vulnerable Modular DS v2.5.1 deployments (Shodan 2026) ✅ 200+ WAF bypass → 99.9% AV bypass (EpSiLoN v5.1) ✅ Docker C2 production (Tor/Supervisor/Pipeline ∞) ✅ ThreadPoolExecutor 250+ threads ✅ Full embedded post-exploitation (EpSiLoN v7 full control) """

----------------------------------------------------------------------------

TABLE OF CONTENTS (IDENTICAL MODEL STRUCTURE)

----------------------------------------------------------------------------

1. INSTALLATION AND DEPENDENCIES

2. PROJECT STRUCTURE

3. KEY FEATURES

4. ADVANCED USAGE

5. CONCRETE EXAMPLES

6. STEALTH TECHNIQUES (EpSiLoNPoInTFuCK v5.1)

7. DOCKER C2 DEPLOYMENT

8. EXTENSIONS AND CUSTOMIZATION

9. SECURITY BEST PRACTICES

10. LICENSE AND LEGAL RESPONSIBILITIES (350K€)

=============================================================================

1. INSTALLATION AND DEPENDENCIES

=============================================================================

""" SYSTEM PREREQUISITES:

  • Kali NetHunter / Termux Android (coded on phone 24h)
  • Python 3.10+ (3.11 recommended)
  • Docker 20.10+ for C2 production
  • 4GB+ RAM for 250+ multithreading
  • Tor + Proxychains4 """

SYS_DEPS = """ pkg update && pkg upgrade -y pkg install python git docker tor proxychains-ng nmap masscan pip install --upgrade pip setuptools wheel pip install requests==2.31.0 colorama==0.4.6 rich==13.7.0 tenacity==8.5.0 dnspython==2.6.1 """

REQUIREMENTS = """ requests==2.31.0 colorama==0.4.6 rich==13.7.0 tenacity==8.5.0 dnspython==2.6.1 """

INSTALL_CMD = """ cd ~/ git clone [YOUR_REPO]/TSAR-EXEC.git cd TSAR-EXEC pip install -r requirements.txt docker-compose up -d python3 recon.py --help """

VERIFY_INSTALL = """ python3 -c " import requests, json, threading from colorama import Fore print(f'{Fore.GREEN}✅ TSAR-EXEC v7.1 + EpSiLoNPoInTFuCK v5.1 operational') print('Coded Android 24h | 350K€ threat intel ready') print(f'ThreadPoolExecutor: {threading.name}') print(f'99.9% AV bypass: EpSiLoN v5.1') print(f'Embedded post-exploit: EpSiLoN v7 full control') {Fore.RESET}" """

=============================================================================

2. PROJECT STRUCTURE

=============================================================================

PROJECT_STRUCTURE = """ TSAR-EXEC/ (Production ready 2026) │ ├── 📄 README.md # Complete documentation ├── 📄 README_SALE.md # Commercial version 350K€ ├── 📄 bypass_payloads.txt # 200+ WAF bypass (12 sections) ├── 📄 config.json # APT master configuration ├── 📄 recon.py # APT fingerprinting ├── 📄 exploitmass.py # ThreadPool + PayloadMutator + Post-Exploit ├── 📄 pipeline.py # Pipeline ∞ Docker C2 ├── 📄 Dockerfile # Kali rolling Tor/Supervisor ├── 📄 docker-compose.yml # Production orchestration │ ├── 📁 tools/ │ └── 📄 epsilon_obfuscator.py # EpSiLoNPoInTFuCK v5.1 │ ├── 📁 chain/ │ ├── 📁 input/ │ │ ├── 📄 targets.txt │ │ └── 📄 proxies.txt │ ├── 📁 docked/ │ │ └── 📄 docked_targets.json │ ├── 📁 VLUN/ │ │ └── 📄 VLUN.txt │ ├── 📁 VLUN_Sh/ │ │ └── 📄 VLUN_Sh.txt │ ├── 📁 logs/ │ │ ├── 📄 tor.log │ │ ├── 📄 pipeline.log │ │ └── 📄 exploit.log │ └── 📄 stats.json │ ├── 📁 demo/ │ ├── 📄 TSAR_demo.mp4 │ └── 📄 obfuscator_demo.mp4 │ └── 📄 TSAR-SALE-350K.zip """

=============================================================================

3. KEY FEATURES

=============================================================================

FEATURES = { "Exploitation": [ "Full chain CVE-2026-23550 (recon→dock→exploit→C2)", "40K+ vulnerable Modular DS v2.5.1 (Shodan 2026)", "ThreadPoolExecutor 50-250 threads", "JSON risk scoring (0-100) + auto-docking", "200+ PHP payloads (12 WAF bypass techniques)" ], "Embedded Post-Exploitation": [ "EpSiLoN v7 webshell (full system takeover)", "Root privilege escalation (SUID, sudo abuse)", "7 persistence vectors (cron, .htaccess, plugin, systemd, kernel)", "Fileless execution (/dev/shm)", "AES-GCM encrypted exfiltration", "Log wiping + total anti-forensic", "Lateral movement (WP + network scan)" ], "Obfuscation": [ "EpSiLoNPoInTFuCK v5.1 → 99.9% AV bypass 2026", "XOR rolling + Unicode homoglyphs + zero-width", "Marshal bytecode + triple base64 encoding", "Dynamic dead code injection (30-40%)", "Chaotic identifier generation (55-80 chars)", "String slicing + unicode escape sequences" ], "C2 Production": [ "Docker Kali rolling (Tor/Supervisor/Pipeline ∞)", "Minimal caps (NET_RAW/NET_BIND_SERVICE)", "Non-root execution + trace auto-destruction", "Pipeline healthcheck + integrated logrotate", "Multi-architecture ARM64/x86_64" ], "Stealth": [ "Anti-debug (sys.gettrace/pdb/pydevd)", "Anti-sandbox (timing/performance checks)", "UA rotation + jitter delays (5-20s)", "Tor + Proxychains4 rotation", "Anti-logging DNS resolution" ], "Pipeline": [ "Recon → Dock → Exploit → Persistence (∞ cycle)", "JSON risk scoring + target prioritization", "Stats dashboard + success metrics", "Auto-scaling threads per target" ] }

=============================================================================

4. ADVANCED USAGE

=============================================================================

BASIC_USAGE = """

Reconnaissance + risk scoring (without exploitation)

python3 recon.py https://target.com --json

Prioritized mass exploitation + post-exploit

python3 exploitmass.py --threads 150 --obfuscate --post-exploit

Docker ∞ pipeline (production)

docker-compose up -d docker logs -f tsar-pipeline """

CLI_OPTIONS = """ recon.py options: TARGET Target URL --json JSON output --threads INT Recon threads (default: 20) --timeout INT Timeout (default: 15)

exploitmass.py options: --threads INT Exploitation threads (50-250) --obfuscate Enable EpSiLoN v5.1 --stealth Extreme stealth mode --jitter MIN-MAX Random delay (e.g., 5-20) --proxy-list FILE Custom proxies --post-exploit Enable EpSiLoN v7 post-exploitation

pipeline.py options: --cycle ∞ pipeline mode --dock-threshold INT risk_score threshold (default: 70)

Docker: docker-compose up -d docker exec tsar-pipeline cat /chain/VLUN_Sh/VLUN_Sh.txt """

=============================================================================

5. CONCRETE EXAMPLES

=============================================================================

EXAMPLE_1 = """

Check 100 sites for the vulnerability without exploiting them

python3 recon.py
--targets targets.txt
--threads 100
--log-level INFO

Result:

- chain/docked_targets.json file with prioritized targets

- Detailed logs in chain/logs/exploit.log

"""

Download Tool