
webvm
Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

Small CTF challenges running on Docker

Scoring Engine for Red/White/Blue Team Competitions

This tool aims at automating the identification of potential service running behind ports identified manually either through manual scan or services…

proof of Concept (PoC) exploit for CVE-2021-31630, targeting the OpenPLC service running on the WifineticTwo box on the Hack The Box platform.

This is a exploit for the known Remote Code Execution (RCE) vulnerability in the `pymatgen` (CVE-2024-23346) Python library by uploading a malicious…


A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

A collection of samples and material related to process injection

HTB Season 10 - Pterodactyl machine writeup. Medium Linux box covering CVE-2025-49132 (Pterodactyl Panel RCE) and CVE-2025-6018/6019 (udisks2…

A simple python script to exploit CVE-2021-31630 on HTB WifineticTwo CTF

Step-by-step lab writeup demonstrating CVE-2019-20933 InfluxDB authentication bypass via forged JWT tokens, including exploitation,…

For CTF use only (the CVE-2019-7214 also resolves the host from /etc/hosts)