
CVE-2022-4096
This experiment is destinated to demonstrate how the DNS rebinding attack works on an emulated IoT. In the setup, we have a simulated IoT device,…

This experiment is destinated to demonstrate how the DNS rebinding attack works on an emulated IoT. In the setup, we have a simulated IoT device,…

CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.

Python script get image from Hikvision camera with CVE-2017-7921 vulnerability

Proof-of-concept exploit for CVE-2024-1303, a path traversal vulnerability in Badger Meter's moni:tool that allows authenticated attackers to…

Proof-of-concept exploit for CVE-2020-25747 demonstrating unauthenticated remote access to RTSP and ONVIF services on Rubetek RV-3406/3409/3411…

Python exploit for CVE-2021-46381 targeting D-Link DAP-1620 arbitrary file read vulnerability with FOFA-based device discovery.

Exploit for CVE-2017-7921 targeting Hikvision devices with improper authentication. Retrieves user lists, camera snapshots, and configuration files…

Exploit tool for CVE-2018-9995 that retrieves DVR credentials via crafted HTTP request, targeting multiple DVR vendors for security testing.

Batch exploit script for CVE-2020-25078 targeting D-Link DCS series cameras to extract account credentials via information disclosure vulnerability.

Build interactive map of cameras from Shodan

.NET console application that exploits CVE-2018-9995 vulnerability