
CVE-2024-27766
Modified PoC for MariaDB v11.1 RCE via UDF, returning command output inline through SQL queries. Includes detailed code comparison and compilation…

Modified PoC for MariaDB v11.1 RCE via UDF, returning command output inline through SQL queries. Includes detailed code comparison and compilation…

Remotely delete access logs, Windows event logs, databases, and files on target machines using automated scanning or manual attack selection for…

This Python 3 script is for uploading shell (and other files) to Windows Server / Linux via Oracle 11g R2 (CVE-2010-3600).

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Advanced MSSQL penetration testing tool for lateral movement, command execution, NTLM relay, and brute-force attacks via linked servers and multiple…

SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.

Windows Oracle Database Attack Toolkit

The latest workaround for the "Query is corrupt" error introduced with CVE-2019-1402

Proof of Concept (PoC) for SQL Injection in Xhibiter NFT Marketplace 1.10.2 (Collections Endpoint). Discovered by Sohel Yousef.

Proof-of-concept for CVE-2021-39378: SQL injection in openSIS 8.0 via the str parameter in NamesList.php, enabling database extraction and blind…

Java JDBC driver for SQLite databases with native library support across major operating systems, enabling standard database connectivity without…

🔎Sniffing and parsing mysql,redis,http,mongodb etc protocol. 抓包截取项目中的数据库请求并解析成相应的语句。


SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit