
CVE-2026-3333-DNS-Rebinding-to-Steal-Cloud-Metadata
Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

A privacy and security engineering toolkit: Discover, understand, pseudonymize, anonymize, encrypt and securely share sensitive and personal data:…

Default Detections for EDR

An open source swiss army knife for arbitrary communication over application protocols

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

An at-rest encrypted filesharing application with multiple clients who seek to share privately, without tracking.

Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

Scanning pastebin with yara rules

Extraction of iMessage Data via XSS

Easy peasy file uploads

PoC exploit for CVE-2026-21015 that abuses PHP filter chains to read arbitrary files through a vulnerable include() call, disclosing source and…

Password Manager Pro Exploit