
attifyos
Attify OS - Distro for pentesting IoT devices

Attify OS - Distro for pentesting IoT devices

A Virtual environment for Pentesting IoT Devices

PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes…

An intelligence gathering tool for hacking Bluetooth

Analysis and cleanup guide for BadBox malware on Allwinner H713 Android projectors: ADB access, infection proof, firmware backup, dropper removal,…

Non-destructive security assessment tool for CVE-2026-73296, checking authentication boundaries on exposed Mobile MCP HTTP servers (ports 8020/8021)…

Proof of concept for CVE-2026-36027 and CVE-2026-36028

Android NFC package patched for CVE-2020-0453, addressing a security vulnerability in the NFC component.

Low Interaction Mobile Honeypot

Reverse engineering the BYD Dolphin head unit — CAN bus, AVAS, NFC keys, OTA, and more. DiLink 3 / Android 10.

HomePwn - Swiss Army Knife for Pentesting of IoT Devices

Proof-of-concept exploit for OS command injection (CVE-2023-33381) in MitraStar GPT-2741GNAC routers. Demonstrates bypass of restricted shell via…

Offensive security tool for printer pentesting

Proof-of-concept exploit for authenticated OS command injection in TP-Link Archer C20 v6 web management interface, executing root commands via BPA…

Python proof-of-concept for unauthenticated OS command injection in TOTOLINK N600R, exploiting the langType parameter to execute arbitrary commands…

Proof of concept for arbitrary OS command execution on Guangzhou/V-SOL 1GE ONU devices (CVE-2020-8958)

Proof-of-concept for authenticated OS command injection in TP-Link router firmware. Includes decryption, QEMU-based encryption hook, and 15-character…

Security program for recovering passwords and pen-testing servers, routers and IoT devices using brute-force password attacks.