
stunner
Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

The code for personally reproducing the corresponding vulnerability

CVE-2026-25049

Vatilon-based IP cameras expose internal web directories without authentication, leading to information disclosure.

Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…

CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles…

Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)

An ADCS honeypot to catch attackers in your internal network.

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

Event-driven AWS security misconfiguration detection framework that monitors multiple accounts in real-time, triggering alerts via Lambda for IAM,…

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls