
stunner
Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

An ADCS honeypot to catch attackers in your internal network.

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

Event-driven AWS security misconfiguration detection framework that monitors multiple accounts in real-time, triggering alerts via Lambda for IAM,…

Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles…

CVE-2026-25049

Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…

The code for personally reproducing the corresponding vulnerability

Vatilon-based IP cameras expose internal web directories without authentication, leading to information disclosure.