
lazyrecon
Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

Python-based exploit generator for Adobe Reader BMP/RLE heap corruption (CVE-2013-2729). Demonstrates arbitrary code execution via malicious BMP…

Test cases for broken MIME and tools to generate and process these

Reproducer and technical analysis for CVE-2026-85048, a Chrome viz surface use-after-free in the GPU process, with ASAN unit tests and browser…

Reproducible crash proof-of-concept for CVE-2015-3456 (VENOM) targeting QEMU's virtual floppy disk controller. Demonstrates guest-controlled writes…

Coverage-guided kernel fuzzing framework that runs XNU as a userspace library and discovers vulnerabilities across BSD, Mach, virtual memory, and…

A lightweight dynamic instrumentation library

Reverse engineering software using a full system simulator

Frida-based in-process fuzzing suite with AFL++ proxy, standalone active/passive modes, and shared memory communication for high-performance…

Coverage-guided in-process fuzzer for iOS Bluetooth daemon (bluetoothd) using FRIDA, with over-the-air fuzzing for MagicPairing protocol and crash…

Tool to make in memory man in the middle

Automated format string vulnerability exploitation tool for discovering stack, PIE, and canary leaks with flag search capability via %s or %p…

Fuzzing Framework for Modules in Apache HTTPD Server

CVE-2024-31317 Debuggable App Exploit

Script to perform automatic initial web and vulnerability recon

Vulnerability Found on Squid Proxy.

Reproduces fuzzing and crash analysis for CVE-2024-1441 using AFL++ and CASR, with detailed setup and commands for libvirt.