
pentest-guide
Penetration tests guide based on OWASP including test cases, resources and examples.

Penetration tests guide based on OWASP including test cases, resources and examples.

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.

🔥 A powerful MongoDB auditing and pentesting tool 🔥


One day based on https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html



exploit for f5-big-ip RCE cve-2023-46747


CVE-2024-38200 & CVE-2024-43609 - Microsoft Office NTLMv2 Disclosure Vulnerability


Modern Web Firewall: stop account takeovers, weak passwords, cloud IPs, DoS attacks, disposable emails

Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).

Basic PoC for CVE-2023-27524: Insecure Default Configuration in Apache Superset

Confluence未授权添加管理员用户(CVE-2023-22515)漏洞利用工具