
payloads
Git All the Payloads! A collection of web attack payloads.

Git All the Payloads! A collection of web attack payloads.

This program Prompts you for the Local File Inclusion information and will automatically search the /etc/passwd and using the users names found will…

Search and extract blob files on the Ethereum Blockchain network

This tool aims at automating the identification of potential service running behind ports identified manually either through manual scan or services…

Some good resources for getting started with application security

CVE-2025-49113 – Roundcube ≤1.6.10 post-auth RCE via PHP object deserialization (HackTheBox CTF)

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.

A list of Capture The Flag (CTF) frameworks, libraries, resources and software for started/experienced CTF players 🚩

Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)

Single-script exploit for CVE-2026-44881 that chains .git credential leakage, Portainer Git-symlink injection, arbitrary host file read, and SSH…