
SafeLine
Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Documentation and reverse engineering of reCAPTCHA

Proof-of-concept exploit for CVE-2026-5411 targeting WP Captcha PRO, demonstrating a vulnerability that bypasses CAPTCHA protections in WordPress…

Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE

Reverse engineering the new Datadome VM 🔥

Vercel BotID Solver "X-Is-Human" using 100% golang

AWS WAF Solver, full reverse implemented in 100% Python & Golang.

Exploit for CVE-2023-3897 enabling username enumeration via CAPTCHA bypass in On-premise SureMDM on Windows. Includes PoC script for local user…

Exploit for CVE-2008-2019 bypassing audio captcha in Simple Machines Forum 1.1.4 using hamming distance and levenshtein distance to compare PCM audio…

D-LINK ROUTER "MODEL NO: DIR-615" with "FIRMWARE VERSION:20.10" & "HARDWARE VERSION:T1

DEPRECATED, wifipumpkin3 -> https://github.com/P0cL4bs/wifipumpkin3

Advanced reconnaissance utility

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!