
SteganographierGUI
将文件隐写进MP4/MKV文件中 (Embed files into MP4/MKV files.)

将文件隐写进MP4/MKV文件中 (Embed files into MP4/MKV files.)

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

Consul Template validated where a symlink pointed during template evaluation, but its later dependency fetch read the original path. Retargeting the…

CVE-2021-26837 - SQL Injection in the SearchTextbox parameter of HelpSystems/Fortra DeliverNow. Payloads, annotated requests, and evidence. Fixed in…

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

Red Team tool for covert file exfiltration via Bluetooth audio transmission, encoding binary data into FLAC signals to bypass EDR, XDR, and DLP…

Cloud Storage using Instagram.

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

This script exploits a stored XSS vulnerability (CVE-2024-42009) in Roundcube Webmail version 1.6.7. It injects a malicious payload into the webmail…

Uscrapper Vanta: Dive deeper into the web with this powerful open-source tool. Extract valuable insights with ease and efficiency, from both surface…

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.