
WPCracker
WordPress pentest tool

WordPress pentest tool

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

These templates are suggestions of how the Obsidian notetaking tool can be used during an OSINT investigation. The example data in those files should…

how to look for Leaked Credentials !

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

How to Install OpenClaw on an Android Phone and Control It via WhatsApp

This OSINT Notebook provides an overview of the tools, techniques, and resources that I use for a variety of situations when it comes to performing…

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

A OSINT project that explores how to dump data from React

Script is a proof of concept how to control your machine by using social media sites.

This vulnerability allows an attacker to perform SSRF (Server-Side Request Forgery) attacks on Apache CXF webservices that accept MTOM/XOP requests.…

Proof of Concept (PoC) for a stack-based buffer overflow in Steghide 0.5.1. Demonstrates how long file paths trigger a crash (DoS) and leak sensitive…

POC shows how to leak postgresql stuff cause hugefile sub-system. Based on https://x.com/spendergrsec/status/1993794163880718700?s=20

On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code…

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

Proof-of-concept for an XXE vulnerability in WorldServer v11.8.2; demonstrates how a crafted .tmx file can leak system files and potentially execute…

How to get access via CVE-2022-27997

Analyzes CVE-2021-42948, a session token exposure vulnerability in HotelDruid, demonstrating how GET parameters leak session IDs and enable session…