
redi
Automated script for setting up CobaltStrike redirectors (nginx reverse proxy, letsencrypt)

Automated script for setting up CobaltStrike redirectors (nginx reverse proxy, letsencrypt)

Step-by-step, image-backed proof-of-concept simulation of OS command injection vulnerabilities (CVE-2024-46256 and CVE-2024-46257) in Nginx Proxy…

Java GUI tool for exploiting CVE-2026-21962, an unauthenticated RCE in Oracle WebLogic Proxy Plug-In, enabling multi-target command execution via…

Python exploit for Moodle Evil Teacher vulnerability (CVE-2018-1133) enabling authenticated remote command execution with proxy support.

Exploit tool for CVE-2024-4577 (PHP-CGI) enabling remote command execution with batch scanning, proxy support, and multi-threaded target processing.

Bypass firewall for traffic forwarding using webshell

Embed a reverse shell in Notion pages using the Notion API as a proxy, enabling stealthy remote shell sessions with encrypted and authenticated…

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

Python exploit for CVE-2025-47812, achieving remote code execution on Wing FTP Server via Lua injection in the login username parameter. Supports…

Exploit and scanner for CVE-2025-47812 targeting Wing FTP Server unauthenticated remote code execution, supporting single-target, mass scanning,…

PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain,…

Python-based exploit for Struts2 S2-061 (CVE-2020-17530) remote command execution vulnerability. Supports single URL, file-based scanning, proxy, and…

Python exploit for CVE-2018-7600 (Drupalgeddon2) enabling remote command execution on vulnerable Drupal sites via property injection in the Forms…

Python Exploitation Framework, V8 Engine Debugger, Proxy interceptor, marketplace, post-exploitation, backdoor generator,....

Scripts for: How to Build a Covert Pentesting Infrastructure Almost Free

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR