
Lucifer
A Powerful Penetration Tool For Automating Penetration Tasks Such As Local Privilege Escalation, Enumeration, Exfiltration and More... Use Or Build…

A Powerful Penetration Tool For Automating Penetration Tasks Such As Local Privilege Escalation, Enumeration, Exfiltration and More... Use Or Build…

Exploit for Apache OFBiz CVE-2024-32113 path traversal via crafted XML-RPC requests, enabling arbitrary file read and potential command execution on…

Proof-of-concept exploit for authenticated arbitrary file read via directory traversal in WordPress Tainacan plugin (CVE-2024-7135).

Exploit for CVE-2024-12849, an arbitrary file read vulnerability in WordPress Error Log Viewer plugin. Downloads sensitive files via unauthenticated…

Pack up to 3MB of data into a tweetable PNG polyglot file.

Lack of argument sanitization leading to password leakage in Ghostscript PDF versions up to 10.05.0.

Backup Telegram chat logs with incremental support, multiple output formats (JSON, HTML, plaintext), and media download via telegram-cli remote…

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

Our Friendly Gmail will act as Server and implant will exfiltrate data via smtp and will read commands from C2 (Gmail) via imap protocol

Azure Post Exploitation Framework

Modified dropbear server which acts as a client and allows authless login

WP SuperBackup <= 2.3.3 - Missing Authorization to Unauthenticated Back-Up File Download