
inter-recon
Script to perform automatic initial web and vulnerability recon

Script to perform automatic initial web and vulnerability recon

PoC exploit server for CVE-2015-7547

Fast and easy-to-use directory brute-forcer written in Go.

Proof-of-concept exploit for CVE-2026-41096: heap overflow in Windows DNS Client's DnsRawTruncateMessageForUdp(). Includes rogue DNS server and…

Tool to discover paths in web applications

CVE-2026-5172: buffer overflow in extract_addresses() on crafted resource record PoC

Automated defect verification tool for 6 dnsmasq CVEs (CVE-2026-2291, 4890, 4891, 4892, 4893, 5172)

Generate the poc for CVE-2026-4893: broken EDNS Client Subnet validation.

Fuzzing the Microsoft Windows DNS client library. Inspired by CVE-2026-41096.

Proof-of-concept for a critical buffer overflow in Kemp LoadMaster's DNS handling, causing remote denial-of-service via crafted DNS requests.

PoC exploit for CVE-2025-5688: remote out-of-bounds write in FreeRTOS-Plus-TCP via crafted LLMNR/mDNS queries, causing crash or potential RCE on…

Proof-of-concept exploit for CVE-2017-9430, a stack-based buffer overflow in dnstracer 1.9, triggered via a long command-line argument causing denial…

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)

Fuzz a list of domains for specific endpoints

CRLF and open redirect fuzzer

Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple…

Gryffin is a large scale web security scanning platform.