

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

Dump Kerberos tickets from the KCM database of SSSD

Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

Tool to spray AWS Console IAM Logins

Exploit for CVE-2023-7028 - GitLab CE/EE





Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.


Proof of concept for CVE-2015-0006. Fixed in MS15-005 https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2015/ms15-005 .

Zeek detection logic for CVE-2022-30216.

F5 BIG-IP RCE exploitation (CVE-2022-1388)

Shell script for testing the IPMI cipher type zero authentication bypass vulnerability (CVE-2013-4784)