
CVE-2025-24204
PoC and technical details of CVE-2025-24204

PoC and technical details of CVE-2025-24204

Trusted localhost HTTPS — local CA, /etc/hosts, mDNS LAN sharing, reverse proxy. Maps https://name.local → localhost:port

Decrypt TP-Link Firmware

A next generation of ransomware. Fully written using a .Net Framework + C&C System

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

FinalShellDecodePass 加密解密

Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.

Compile-time AES string obfuscation for C++

Easy XOR string encryption for NET based binaries

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…

An extensible, end-to-end encrypted reverse shell that works across networks without port forwarding.

Detection and sanitization for Acropalypse Now - CVE-2023-21036

Exploit and tooling for Amlogic-based Sonos devices: dumps OTP/eFUSE via an EL3 exploit, extracts LUKS decryption keys, and fetches/decrypts OTA…

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Python based tool for generating Shellcode from PIC C

bad stuffs by bad guys