
MaliciousBrowserExtensions
This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one…

This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one…

GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.

FluxER - The bash script which installs and runs the Fluxion tool inside Termux. The wireless security auditing tool used to perform WPA/WPA2…

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

Open-source URL masking & analysis tool for security research, phishing awareness, and defensive testing. Demonstrates adversary techniques used to…

A script used to create a whonix like gateway/workstation environment with docker containers.

An app with really insecure crypto. To be used to see/test/exploit weak cryptographic implementations as well as to learn a little bit more about…

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

BLEBoy is a training tool to teach users about BLE security by providing a single BLE peripheral that can be used to experiment with each BLE pairing…

A demonstration of how page tables can be used to run arbitrary code in ring-0 and lead to a privesc. Uses CVE-2016-7255 as an example.

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

Exploit I used to claim 10% final-grade extra credit in Matthew Might's Compilers class.

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

ZIP Bomb Creator is a tool used to create a ZIP file that is small in size but drastically expands when extracted.

used to generate a valid attack chain to exploit CVE-2017-11774 tied to iranian apt only reasearch poc dont use for harm please

Python3 script that can be used to demonstrate **CVE-2025-55182**. It exploits a server-side JavaScript injection vulnerability in Next.js/React…

Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of…

Exploit for CVE-2019-19030 that affects Harbor versions <1.10.3 and <2.0.1. Can also be used to enumerate and pull public projects from higher…