
learnjavabug
Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…

SSH Zero-Day Made By ClumsyLulz

Python exploit for Serv-U SSH vulnerability (CVE-2021-35211) with multiple payload modes: stage, exec, and download-execute, enabling shellcode…

Reproduction of cve-2025-32433-erlang_ssh_rce_reproduction

Erlang/OTP SSH 远程代码执行漏洞

DLL Injection tool to unlock guest VMs

This is a POC I wrote for CVE-2024-6387

Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.

Proof-of-concept exploit for CVE-2024-6387 targeting vulnerable OpenSSH servers via heap manipulation and race condition to achieve remote code…

MIRROR of the original 32-bit PoC for CVE-2024-6387 "regreSSHion" by 7etsuo/cve-2024-6387-poc

Exploit for Ubuntu 20.04 using CVE-2021-3156 enhanced with post-exploitation scripts

This is a basic ROP based exploit for CVE 2020-14871. CVE 2020-14871 is a vulnerability in Sun Solaris systems libpam library, and exploitable over…

Exploit for CVE-2018-17961 targeting evince to bypass execute-only permissions and achieve privilege escalation via ~/.bashrc injection.

Proof-of-concept exploit for CVE-2017-1000117 (Git clone command injection) targeting SSH, designed for vulnerability testing and educational lab…

Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.

Proof of concept python script for regreSSHion exploit.

This exploit script is designed to simplify exploitation of the Erlang/OTP SSH vulnerability CVE-2025-32433 in the TryHackMe lab environment.

Python exploit for CVE-2018-10933, a server-side authentication bypass in libssh versions 0.6 and later. Provides proof-of-concept code for testing…