
HTTP-Shell
Multiplatform HTTP reverse shell providing a shell-like interface over HTTP, with file upload/download, command history, auto-reconnection, and sudo…

Multiplatform HTTP reverse shell providing a shell-like interface over HTTP, with file upload/download, command history, auto-reconnection, and sudo…

Modified CVE-2022-30190 exploit tool for MS-MSDT Office RCE with custom docx template support, binary/command execution modes, and embedded HTTP…

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

Golang binary for data exfiltration with ICMP protocol (+ ICMP bindshell, http over ICMP tunneling, ...)

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

HTTP Server serving obfuscated Powershell Scripts/Payloads

Python-based exploit for CVE-2018-1273 (Spring Data Commons RCE) with interactive command shell and HTTP POST payload injection for penetration…

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

Python backdoor that uses http post/get requests to communicate

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

Proof-of-concept exploit for CVE-2019-3980 enabling remote command execution via custom C# payload with HTTP callback for output retrieval.

Burp Suite/antsword - Interactive shell (HTTP hijack + POST + AES-256-CBC/BASE64)

Remote code execution exploit for Drupal CVE-2018-7600 (Drupalgeddon2) with command injection via HTTP requests.

Exploit for CVE-2018-3191 targeting Oracle WebLogic servers. Generates a malicious payload via RMI, deploys reverse shell classes on an HTTP server,…

Proof-of-concept exploit for CVE-2024-29973, a command injection vulnerability in Zyxel NAS devices. Executes arbitrary OS commands via a crafted…

Python-based exploit script for Oracle WebLogic CVE-2020-14882 unauthorized bypass RCE. Tests authentication bypass and remote code execution via…

Python exploit script for CVE-2019-16278, a remote command execution vulnerability in Nostromo httpd. Executes arbitrary commands on vulnerable…