
metasploit-modules
Collection of proof-of-concept Metasploit modules for exploitation and post-exploitation testing, providing custom payloads and auxiliary functions…

Collection of proof-of-concept Metasploit modules for exploitation and post-exploitation testing, providing custom payloads and auxiliary functions…

Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567

CTT-enhanced version of the Microsoft Exchange Server SSRF to RCE exploit (ProxyShell/ProxyLogon), another CVSS 10.0 critical vulnerability that…

Exploit for CVE-2021-4034, a memory corruption vulnerability in pkexec of polkit, enabling local privilege escalation to root on Linux systems.

Proof Of Concept for the 2021's pkexec vulnerability CVE-2021-4034

Welcome to the Metasploit Exploits Repository, your go-to resource for a comprehensive collection of cutting-edge exploits designed for penetration…

This Metasploit module exploits an unauthenticated remote code execution vulnerability which exists in Apache version 2.4.49 (CVE-2021-41773). If…

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

This tool demonstrates the application of fundamental physics discoveries to cybersecurity.

Full-lifecycle penetration test of a legacy Linux environment (Metasploitable 2) emulated on Apple Silicon. Demonstrating network reconnaissance, RCE…

Educational demonstration of exploiting CVE-2017-0143 (EternalBlue) on Windows 7 using Metasploit in a controlled lab environment for penetration…

A hands-on vulnerability assessment and exploitation of a Windows 7 VM using the EternalBlue (CVE-2017-0143) exploit. Includes scanning, exploitation…

Proof of Concept for CVE-2021-4034 (with experimental traceless exploitation)

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

Rust implementation of the CVE-2021-4034 pkexec privilege escalation exploit, with scripts to download and unpack a vulnerable pkexec for testing.

Modified version of auxiliary/admin/http/tomcat_ghostcat, it can Read any file

Educational exploit reproduction of CVE-2017-7269, a buffer overflow in IIS 6.0 WebDAV, with setup guide, vulnerability analysis, and Metasploit…

cve-2007-2447 this script was rewrite the part of Metasploit modules to python3