

Test and validate Log4Shell (CVE-2021-44228) mitigation approaches with a sample vulnerable Log4j app, including JNDI exploitation, environment…

A lab for playing around with the Log4J CVE-2021-44228

PoC for CVE-2021-43557

Vulnerable REACT app in docker container and poc code - for demos

POC for CVE-2024-4701

DO NOT USE FOR ANYTHING REAL. Simple springboot sample app with vulnerability CVE-2021-44228 aka "Log4Shell"

Docker-based vulnerable environment for practicing CVE-2023-30212 exploitation, featuring an OURPHP web app with a reflected XSS vulnerability for…

AndroSH No-Root Multi-Distro Linux on Android via Shizuku/ADB - Run Arch, Fedora, Alpine, Debian, Ubuntu, Kali, Void, Manjaro, OpenSUSE & Chimera…

Reproducible Docker lab for CVE-2018-15133 (Laravel Framework token unserialize RCE) with a known APP_KEY and a /poc route for testing exploit…

Educational demo of CVE-2024-21626 runc container escape with eBPF-based detection gadget for exploitation attempts.

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

3 linux kernel bugs chains to do secure comm app using side channel to establish key and establish covert channe;

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

A rootless Android app that boots Alpine Linux: run containers (Podman/Docker/LXC) and GUI desktop apps.

A self hosted virtual browser that runs in docker and uses WebRTC.

An app that helps you monitor your Kubernetes cluster, debug critical deployments & gives recommendations for standard practices

Vulnerable app with examples showing how to not use secrets