
haaukins
A Highly Accessible and Automated Virtualization Platform for Security Education

A Highly Accessible and Automated Virtualization Platform for Security Education

Proof-of-concept exploit for CVE-2026-52199: unauthenticated remote code execution via exposed ADB daemon on UZ801 4G LTE router. Includes…

Classic stack-based buffer overflow in War FTP Daemon 1.65 demonstrating old-school remote code execution through malformed FTP commands.

Proof-of-concept exploit for CVE-2025-32433, a pre-authentication RCE in Erlang/OTP SSH daemon. Includes Python script to send crafted SSH channel…

Exploiting the vulnerability called "Dirty_Sock" (CVE-2019-7304) in the REST API for Canonical's snapd daemon.

Pre-authentication Remote Code Execution exploit for TP-Link Omada ER605 router via DDNS client daemon (cmxddnsd)


ProFTPd 1.3.5 - (mod_copy) Remote Command Execution exploit and vulnerable container

CTF-style Docker lab for CVE-2026-41651 (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation

FortiOS buffer overflow vulnerability

GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.

Local privilege escalation exploit targeting PackageKit's TOCTOU race condition (CVE-2026-41651). Escalates from unprivileged user to root via polkit…

Python exploit for the vsFTPd 2.3.4 backdoor (CVE-2011-2523).

Technical analysis of the cPanel/WHM auth bypass

vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption