
NebulaPulsar
In-memory implant framework for Java and ASP.NET webshells with AES-encrypted communication, dynamic payload loading, and session-based execution for…

In-memory implant framework for Java and ASP.NET webshells with AES-encrypted communication, dynamic payload loading, and session-based execution for…

CodeIgniter <=2.1.4 session cookie decryption vulnerability

Burp Suite extension for interactive data extraction and transformation in HTTP traffic with configurable node tree supporting Base64, JSON, XML, URL…

Decrypts AES-encrypted web requests and integrates with Intruder for automated brute-force cracking of login credentials via custom payload processor.

Python Implementation of a .NET Padding Oracle Assessment Tool

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

Burp Suite/antsword - Interactive shell (HTTP hijack + POST + AES-256-CBC/BASE64)

Decrypt and re-encrypt Laravel session cookies to exploit insecure PHP deserialization for remote code execution.

Java-based exploit tool for reading and decrypting database configuration files from vulnerable Fanwei OA instances by accessing a specific JSP…

Batch scanner for Hikvision cameras vulnerable to CVE-2017-7921, automating configuration file decryption and credential extraction, with…

A vulnerability can allow an attacker to guess the automatically generated development mode secret token.

Python toolkit for authorized testing of CVE-2021-43798 Grafana path traversal, with arbitrary file read PoC, secret decryption, and user hash export…

Mass scanner for Laravel apps vulnerable to CVE-2024-55555, automating APP_KEY brute-force to detect unauthenticated RCE in Invoice Ninja.

Python script exploiting CVE-2018-0114 to forge JWT tokens by embedding attacker-controlled public keys in JWS headers, bypassing signature…

Exploit tool for CVE-2026-27944 targeting Nginx UI unauthenticated backup download and decryption, with mass scanning, credential extraction, and…

Rust-based brute-force scanner for Laravel APP_KEYs: inlines AES-NI decryption, supports single and batch key testing against encrypted ciphertexts.

Combined exploit for Telerik UI ASP.NET AJAX, enabling arbitrary file upload and .NET deserialization attacks with encryption/decryption of…

PoC exploit for CVE-2022-35513 that decrypts weakly encrypted passwords from the Blink1Control2 API server, reversing ciphertext found at the…