
hulak
Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

Batch scanner for Hikvision cameras vulnerable to CVE-2017-7921, automating configuration file decryption and credential extraction, with…

Exploit tool for CVE-2026-27944 targeting Nginx UI unauthenticated backup download and decryption, with mass scanning, credential extraction, and…

In-memory implant framework for Java and ASP.NET webshells with AES-encrypted communication, dynamic payload loading, and session-based execution for…

Rust-based brute-force scanner for Laravel APP_KEYs: inlines AES-NI decryption, supports single and batch key testing against encrypted ciphertexts.

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

Python toolkit for authorized testing of CVE-2021-43798 Grafana path traversal, with arbitrary file read PoC, secret decryption, and user hash export…

Proof-of-concept exploit demonstrating JWT/JWE authentication bypass by forging unverified tokens with alg:none, wrapped in valid JWE encryption…

Burp Suite extension for testing SAML infrastructures. Manipulate SAML messages, perform signature spoofing, XSW, XXE, and XSLT attacks, and manage…

A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications.

Automated exploitation toolkit for Hikvision IP cameras. Performs snapshot access, config decryption, credential extraction, and remote command…

Burp Suite/antsword - Interactive shell (HTTP hijack + POST + AES-256-CBC/BASE64)

Compresses EXE/DLL payloads into password-protected 7z/zip archives, XOR-encrypts them, and hides them inside PNG/GIF images for covert HTML…

A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt…

Decrypts Hikvision IP camera configuration files extracted via CVE-2017-7921 authentication bypass, recovering user credentials from weakly encrypted…

Exploit for Apache RocketMQ CVE-2019-17572 targeting distributed messaging platforms with authentication and encryption features.

Mass scanner for Laravel apps vulnerable to CVE-2024-55555, automating APP_KEY brute-force to detect unauthenticated RCE in Invoice Ninja.

Exploit for CVE-2024-43044 enabling arbitrary file read from Jenkins controller to extract and decrypt credentials.xml using secret keys.