
Static-Malware-Analysis-Follina-CVE-2022-30190
Static Malware Analysis of Follina (CVE-2022-30190) from Blue Team Labs Online

Static Malware Analysis of Follina (CVE-2022-30190) from Blue Team Labs Online

This is a minimal, educational simulation that demonstrates the _impact_ class of a management-plane parsing RCE (inspired by CVE-2025-20265). It…

This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in…

PoC Python script as an exercice from tryhackme.

A fun activity using a packet capture file from the log4j exploit (CVE-2021-44228)

A cybersecurity case study analysing CVE-2023-20198 in Cisco IOS XE, covering vulnerability exploitation, mitigation strategies, secure software…

This lab simulates CVE-2019-9193 - PostgreSQL COPY FROM PROGRAM RCE

This is an Exploit App I made when solving the DocumentViewer challenge (CVE-2021-40724) from MobileHackingLab. It will download a libdocviewe_pro.so…

A hands on lab investigating CVE-2025-39507 from a Tier 1 SOC analyst perspective. Includes log review in Microsoft Sentinel, IP analysis, real world…

Log4Shell Proof-Of-Concept derived from https://github.com/kozmer/log4j-shell-poc

Self-contained lab environment that runs the exploit safely, all from docker compose

this is my simple article about CVE 2022-30190 (Follina) analysis. I use the lab from Letsdefend.

Proof-of-concept RCE for Langflow CVE-2026-33017 using a malicious custom component to execute OS commands via build_public_tmp and retrieve output…

A write up on the Steel Mountain box from TryHackMe.com and exploit for CVE-2014-6287

Research on GraphQL from an AppSec point of view.

Full Metasploit exploitation walkthrough against Metasploitable2 — vsftpd backdoor, Samba CVE-2007-2447, UnrealIRCd backdoor, Netcat exfiltration,…


Collection of methodology and test case for various web vulnerabilities.