
squarephish
Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

Spoof SSDP replies and create fake UPnP devices to phish for credentials and NetNTLM challenge/response.

This function combines all the above functions and takes necessary information from the user to change the IP and MAC address, start the responder…

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

A Telegram Mass Surveillance Bot in Python

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…


A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

A DNS spoofer tool written in Python3.

Repository for CVE-2023-4281 vulnerability.

Repository for CVE-2023-4631 vulnerability.

Repository for CVE-2023-4279 vulnerability.