
DataSurgeon
Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text

Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text

Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)

A simple HTTP server for delivering and exfiltrating files/data during, for example, CTFs.

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Stored XSS exploit for Roundcube Webmail ≤1.6.6 (CVE-2024-42009) with zero-click email exfiltration via CSS animation event handlers. Includes SMTP…

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

RSA attack tool (mainly for ctf) - retrieve private key from weak public key and/or uncipher data

Fast Steganography bruteforce tool written in Rust useful for CTF's

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash

AI-driven OSINT and security research agent that builds a live knowledge graph from public data, with bundled recon tools and offensive-security…

An automatic Blind ROP exploitation tool

Official repository for CTFTiny

A Python PoC for CVE-2022-21661, adapted from z92g's Go PoC, designed to demonstrate the vulnerability in a more accessible scripting environment.

Solutions and write-ups for Flare-On 11 CTF challenges, showcasing reverse engineering, binary analysis, and malware analysis techniques with…

Source-code solutions to Flare-On 10 reverse engineering challenges, demonstrating binary and malware analysis techniques for CTF-style reversing…

Step-by-step CTF walkthrough exploiting the vsftpd 2.3.4 backdoor (CVE-2011-2523) to capture and crack /etc/shadow and /etc/passwd from…