
TwoMillion-Machine-Writeup
From deobfuscating code.js to root, CVE-2023-0386

From deobfuscating code.js to root, CVE-2023-0386

Proof-of-concept for CVE-2024-37726: local privilege escalation in MSI Center via arbitrary file overwrite using symlink/junction attacks and OpLock…

Arbitrary file read exploit for the Windows UPnP Device Host service.

Exploit for SaltStack CVEs (CVE-2020-11651/11652) enabling remote command execution on master/minions, file read/upload, and reverse shell.

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

Exploit for Checkmk CVE-2024-0670 with automated file transfer, reverse shell, and privilege escalation via RunasCs for penetration testing…

Proof-of-concept exploit for CVE-2024-31771 demonstrating arbitrary file write in TotalAV via symbolic link attack, enabling DLL planting and SYSTEM…

Proof of Concept for EFSRPC Arbitrary File Upload (CVE-2021-43893)

CVE-2025-27591 – Meta below symlink following local privilege escalation (HackTheBox CTF)

POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a…

Proof-of-concept exploit for CVE-2024-24919, an unauthenticated file read in Check Point Security Gateways; scans single or multiple IP targets and…

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

OSWE, OSEP, OSED, OSEE

My experiments in weaponizing Nim (https://nim-lang.org/)

Android Remote Access Trojan

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup