
exploits and proof-of-concept vulnerability demonstration files from the team at Hacker House
Exploits and proof-of-concept code from the team at Hacker House.
| Filename | Description |
|---|---|
| AirWatchMDMJailbreakBypass.txt | Bypass jailbreak detection on mobile device management AirWatch for IOS |
| adobe-psp.tgz | Adobe CoolType SING Table "uniqueName" Stack Buffer Overflow PSP bypass (metasploit) |
| aix53l-libc.c | AIX 5.3L libc locale environment handling local root exploit |
| aix53l-lquerypv.c | AIX 5.3L /usr/sbin/lquerypv local root privilege escalation |
| amanda-amstar.txt | Advanced Maryland Automatic Network Disk Archiver local root privilege escalation exploit |
| amanda-backup.txt | Advanced Maryland Automatic Network Disk Archiver local root privilege escalation exploit |
| applejack.c | PonyOS 3.0 & below tty ioctl() kernel local root exploit |
| asus_B1M_projector_root.png | ASUS B1M projector remote root command injection (unpatchable) |
| BTCPE.txt | British Telecom Huawei UART root access weakness |
| charybdis.tgz | Firefox & IE exploits implant dropper for Windows & Linux |
| cisco-asa-sslbypass.py | Cisco ASA 8.x & below VPN SSL module Clientless URL-list control bypass |
| cisco-XSS-wget-me.txt | Cisco IOS 11.x web interface XSS vulnerability |
| cmd_gpbypass.exe | cmd.exe patched to run even when disabled via Group Policy |
| cpg15x-dirtraversal.txt | Coppermine 1.5.44 & below directory traversal vulnerability |
| cve-2003-0001.py | CVE-2003-0001.py Etherleak information leak exploit, silently fixed in Cisco ASA PSIRT-0669464365 |
| CVE-2012-4681.tgz | Oracle Java SE 7 Update 6 & below remote polymorphic exploit (evades PSP) |
| CVE-2014-0160.py | Heartbleed mass-scanning proof-of-concept tool |
| cve-2016-1531.sh | Exim 4.84-3 local root exploit |
| cve-2019-10149.py | Exim between 4.87 & 4.91 local root exploit |
| CVE-2020-0601.xdb | XCA database of private keys for trusted CA exploit CVE-2020-0601 |
| CVE-2020-3950.tgz | EvilOSX trojan exploit plugin for CVE-2020-3950 VMware Fusion 11.5.2 & below local root |
| cve-2025-21204.zip | IIS exploit files PoC for insecure "inetpub" configuration cve-2025-21204 |
| d3_decimator.txt | SedSystems D3 decimator multiple vulnerabilities allow for remote root |
| dllpack.tgz | MS15-051 / MS15-010 exploits with reflective DLL loading support (hacked from public code) |
| drupal-CVE-2014-3660.py | Drupal XXE libxml2 Services exploit |
| dtappgather-poc.sh | dtappgather local root exploit proof-of-concept (EXTREMEPARR) |
| fluttershy.py | PonyOS 4.0 runtime linker local root exploit |
| FreeBSD-pftp-dirtraversal.txt | Peters Anonymous FTP on FreeBSD directory traversal vulnerability |
| getlogin.c | Tru64 V5.1B & below getlogin() kernel information leak |
| gionight.py | GIO Linux embedded remote root exploit |
| gns3super-osx.sh | GNS-3 OS-X local root exploit |
| goodnight.c | Linux kernel 2.6.37 & below denial-of-service exploit CVE-2010-4165 |
| heartbleed-bin | static bin heartbleed exploit (fun trivia, Large Hadron Collider tested with this code) |
| heartbleed.c | Heartbleed exploit using OpenSSL to encrypt the exploit for stealth |
| heartbleed-keyscan.py | RSA prime factorization exploit for use with heartbleed |
| hfirixwfcmd.sh | SGI IRIX <= 6.5.22 WebForce post-auth Remote Command Injection |
| hfsunsshdx.tgz | SunSSH Solaris 10-11.0 x86 libpam remote root exploit CVE-2020-14871 |
| hpwhytry.py | HP XPe embedded devices remote command execution exploit |
| iis_search.pl | IIS WebDAV & Indexing service directory traversal attack |
| inetutils-telnet.txt | Multiple BSD based telnet implementations vulnerable to memory corruption. |
| iPwn.tgz | IOS default root user "alpine" exploit to harvest data via SSH |
| irix-captest.c | SGI IRIX <= 6.5.22 capability hijacking "eip" proof-of-concept (SGI XFS) |
| irix-ftpd-ls.txt | SGI IRIX <= 6.5.22 ftpd "/bin/ls" root privilege escalation |
| irix-mediarecorder.txt | SGI IRIX <= 6.5.22 CAP_SCHED_MGT "mediarecorder" privilege escalation |
| irix-onyx-syssgi.c | SGI IRIX <= 6.5.5 syssgi() Onyx IP19/IP21/IP25 kernel information leak exploit |
| irix-rldx.sh | SGI IRIX <= 6.4.x run-time linker file creation exploit |
| irix-runpriv-cap.png | SGI IRIX <= 6.5.x screenshot showing "capabilities" exploit via runpriv |
| irix-setsockopt.c | SGI IRIX <= 6.5.22 kernel mbuf corruption due to integer signedness comparison |
| irix-syssgi-panic.c | SGI IRIX <= 6.5.22 syssgi() SGI_ENUMASHS null ptr kernel panic |
| irix-tapex.c | SGI IRIX <= 6.5.22 "tsdaemon" root arbitrary file creation exploit |
| irssi-irc-fuzzer.pl | irssi plugin IRC client fuzzing tool |