
CnC-Botnet-in-Python
C&C Botnet written in Python with fabric

C&C Botnet written in Python with fabric

CVE-2025-33053 Proof Of Concept (PoC)

CVE-2019-1040 with Kerberos delegation

Cockpit: Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection

AtMail Email Server Appliance 6.4 - Exploit toolchain (XSS > CSRF > RCE)

OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.

CVE-2022-1388-PocExp,新增了多线程,F5 BIG-IP RCE exploitation

包括能执行的命令探测和一键getshell(需要服务器部署服务)

GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability

oPanel Authanticated Remote Code Execution via 'advenced/curl' Component

Telegram Bot to manage botnets created with struts vulnerability(CVE-2017-5638)

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

基于Pocsuite3 框架编写的漏洞验证与利用脚本,用于检测 n8n工作流自动化工具中的认证后远程代码执行漏洞(RCE)

Chain CVE-2019-11408 – XSS in operator panel and CVE-2019-11409 – Command injection in operator panel.

Socks proxy, and reverse socks server using powershell.

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

A Golang implant that uses Slack as a command and control server