
Malicious-MCP
A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

Exploit for CVE-2022-4539 that spoofs X-Forwarded-For headers to bypass WordPress WAF IP-based login and logging restrictions. Includes scalable…

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Incriminator is an OpenSource Project with educational purposes that allows you to incriminate other devices during a cybercrime.

Ask a TGS on behalf of another user without password

This is Advance Phishing Tool ! OTP PHISHING

A Python module to bypass Cloudflare's anti-bot page.

Spoof SSDP replies and create fake UPnP devices to phish for credentials and NetNTLM challenge/response.

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Pass the Hash to a named pipe for token Impersonation

Some scripts to abuse kerberos using Powershell