
Mysql-Readfile
Mysql-Readfile

Mysql-Readfile

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.

Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace

baton drop (CVE-2022-21894): Secure Boot Security Feature Bypass Vulnerability

High speed/Low cost CommonCrawl RegExp in Node.js

Search (offline) if your password (NTLM or SHA1 format) has been leaked (HIBP passwords list v8)

OSINT tool to search, parse and dump only the open Elasticsearch and MongoDB directories that have the data you care about exposing

VeilTransfer is a data exfiltration utility designed to test and enhance the detection capabilities. This tool simulates real-world data exfiltration…

Modified dropbear server which acts as a client and allows authless login

This binary POC automates the exploitation of CVE-2024-36991 by sending crafted curl requests to a vulnerable Splunk instance. It retrieves sensitive…

A Python3 based C2 server to make life of red teamer a bit easier. The payload is capable to bypass all the known antiviruses and endpoints.

Proof-of-concept exploit for authenticated arbitrary file read via directory traversal in WordPress Tainacan plugin (CVE-2024-7135).

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

Find and redact secrets in AI coding agent histories (Claude Code, and more).

MAD-CAT (Meow Attack Data Corruption Automation Tool) is a comprehensive security tool designed to simulate data corruption attacks against multiple…

Payload generator and extractor for CVE-2022-44268 written in Python.

Password Manager Pro Exploit

proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more…