
FDsploit
File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

Easy Grade Pro 4.1 file parsing bug used as an educational example to show how beginners can start vulnerability research through reverse engineering.

Exploit for CVE-2016-2334: heap overflow in 7zip's HFS+ archive parser. Includes HFS+ file generator and WinDbg heap analysis scripts for debugging…

Documentation of a denial-of-service vulnerability in the Rizin reverse engineering framework's ELF parser, caused by a forged DT_VERNEEDNUM value…

Proof of concept for CVE-2022-34913

Proof of concept for CVE-2022-41220

Zip file format fuzzer and multi-tool.

Tool to make in memory man in the middle

Proof-of-concept scanner for CVE-2024-38475 (SonicBoom) Apache URL traversal. Automates TLS negotiation, directory scanning, traversal verification,…

This is the full file system fuzzing framework that I presented at the Hack in the Box 2020 Lockdown Edition conference in April.

A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

Proof-of-concept exploit for CVE-2025-11579, a denial-of-service vulnerability in rardecode that triggers an out-of-memory crash via a crafted RAR…

Tool to help exploit XXE vulnerabilities

Proof-of-concept exploit for CVE-2026-8461, generating a crafted AVI file that triggers a crash in unpatched ffmpeg versions.
