
webvm
Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

Scoring Engine for Red/White/Blue Team Competitions

Step-by-step lab writeup demonstrating CVE-2019-20933 InfluxDB authentication bypass via forged JWT tokens, including exploitation,…

HTB Season 10 - Pterodactyl machine writeup. Medium Linux box covering CVE-2025-49132 (Pterodactyl Panel RCE) and CVE-2025-6018/6019 (udisks2…

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

A collection of samples and material related to process injection

This is a exploit for the known Remote Code Execution (RCE) vulnerability in the `pymatgen` (CVE-2024-23346) Python library by uploading a malicious…

For CTF use only (the CVE-2019-7214 also resolves the host from /etc/hosts)


A simple python script to exploit CVE-2021-31630 on HTB WifineticTwo CTF

proof of Concept (PoC) exploit for CVE-2021-31630, targeting the OpenPLC service running on the WifineticTwo box on the Hack The Box platform.

This tool aims at automating the identification of potential service running behind ports identified manually either through manual scan or services…

Small CTF challenges running on Docker