
HTTPUploadExfil
A simple HTTP server for delivering and exfiltrating files/data during, for example, CTFs.

A simple HTTP server for delivering and exfiltrating files/data during, for example, CTFs.

HTTP Request Smuggling lab: Apache 2.4.55 CRLF injection

Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth

CVE-2025-64446 - A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0…

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

Proof-of-concept exploit for CVE-2025-55182, a remote code execution vulnerability in React Server Functions (Next.js). Demonstrates prototype…

In this project, I documented a detailed penetration testing process targeting Apache HTTP Server vulnerabilities, specifically CVE-2021-41773 and…

A malicious LDAP server for JNDI injection attacks

Collections of Orange Tsai's public presentation slides.

Private Nginx Rift ASLR lab, exploit chain, and demo recordings

Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)

Detailed writeup of CVE-2021-41773 Apache path traversal and RCE exploitation, with step-by-step commands and root cause analysis from a TryHackMe…

CVE-2017-12615 Tomcat: Remote Code Execution via JSP Upload Home Lab for Red Teaming, Penetration Testing

CPH:SEC WAES: Web Auto Enum & Scanner - Auto enums website(s) and dumps files as result