
dns-zone-audit
This Bash script checks domains for DNS zone transfer misconfigurations (CVE-1999-0532). It queries name servers and attempts AXFR requests; if…

This Bash script checks domains for DNS zone transfer misconfigurations (CVE-1999-0532). It queries name servers and attempts AXFR requests; if…

Bash script to patch for CVE-2024-2961

Docker-based lab for exploring and reproducing the Next.js CVE-2025-29927 middleware authorization bypass vulnerability. Includes vulnerable app,…

Generates SCAP, Ansible, Bash, and CEL security content for compliance evaluation and automated hardening across Linux hosts, containers, and…

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

Proof-of-concept for Git LFS pointer poisoning, with Bash and Python scripts that create a malicious repository, simulate a rogue LFS server, and…

Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer/ CIS Benchmark

Log4J checker for Apache CVE-2021-44228

Bash script to detect vulnerable XZ Utils versions (CVE-2024-3094) and downgrade to a safe release, supporting multiple Linux distributions and…

Bash script to detect and remediate CVE-2024-3094, a critical supply-chain vulnerability in the XZ Utils library, with automatic safe version…

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

Checks a shared hosting environment for CVE-2017-9798

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

CosmicSting (CVE-2024-34102) POC / Patch Validator

DEPRECATED: Chef cookbook to audit & remediate "Shellshock" (BASH-CVE-2014-7169)

Mitigate log4shell (CVE-2021-44228) vulnerability attacks using Nginx LUA script

Apply class remove process from ear/war/jar/zip archive, see https://logging.apache.org/log4j/2.x/

A simple script to remove Log4J JndiLookup.class from jars in a given directory, to temporarily protect from CVE-2021-45046 and CVE-2021-44228.