
CVE-2026-78905-Facebook-Account-Takeover
Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.

Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.

Proof-of-concept exploit for CVE-2026-25050, a timing attack enabling user enumeration via GraphQL authentication. Measures response times to…

A Python package and CLI for parsing aggregate and forensic DMARC reports

Remote operations commands implemented using Beacon Object Files

Collection of tools to use with Azure Applications


Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it

USBCoercer turns an ESP32 development board with native USB-OTG into an Ethernet-over-USB gadget capable of coercing proxy configuration via WPAD.

Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

Facebook brute forcer script

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Proof-of-concept exploit demonstrating OTP bypass in One Identity Cloud Access Manager 8.1.3 via MITM/SSL-strip, SAML response replay, and injected…

Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking,…

Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Powershell script to create malicious SMB or WebDAV links to steal NTLM authentication