
VulnHub-DC1-Writeup
VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms

Penetration test walkthrough on a vulnerable Ubuntu VM. Exploited the ProFTPD 1.3.3c backdoor (CVE-2010-4221) to gain root access and capture the…

Linux local privilege escalation exploit for CVE-2026-31431, abusing the AF_ALG crypto API with splice() to modify page cache and spawn a root shell.

Automated Mass Exploiter

Minimal 587-byte static ELF exploit for CVE-2026-31431, achieving local privilege escalation via AF_ALG splice page cache corruption. No libc or…

A little tool to play with Windows security

PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.

A tool that is used to hunt vulnerabilities in x64 WDM drivers

Modular penetration testing platform that enables you to write, test, and execute exploit code.

Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.

ROP ROCKET is an advanced code-reuse attack framework, with extensive ROP chain generation capabilities, including for novel Windows Syscalls attack,…

Local privilege escalation exploit for CVE-2023-36802 targeting Windows kernel streaming service (MSKSSRV) on Windows 11 22H2, using I/O Ring…

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

Public repository for improvements to the EXTRABACON exploit

Exploit for CVE-2023-0179, a stack buffer overflow in the Linux nftables subsystem, enabling unprivileged local privilege escalation to root via…

Exploit for CVE-2026-31431, a Linux kernel AF_ALG AEAD page-cache write vulnerability enabling unprivileged arbitrary 4-byte writes to readable files…