
HostileSubBruteforcer
Subdomain brute-forcing tool that enumerates existing subdomains and detects misconfigured cloud-hosted subdomains vulnerable to takeover across AWS,…

Subdomain brute-forcing tool that enumerates existing subdomains and detects misconfigured cloud-hosted subdomains vulnerable to takeover across AWS,…

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Now, the Host is Mine! - Super Fast Sub-domain Takeover Detection!

Host PHP Info <= 1.0.4 - Missing Authorization to Unauthenticated Sensitive Information Disclosure

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

short view of ruby on rails properties misconfiguration

Automated scanner for exposed Laravel .env files and debug mode, checking misconfigurations via host resolution and IP-based .env access.

Docker base image with backported Host header validation fix for CVE-2025-12543 in Undertow 1.4.x, enabling secure deployment of WildFly 11…

Proof-of-concept exploit for CVE-2025-34159 demonstrating Docker Compose injection in Coolify, enabling low-privileged users to achieve root-level…

Proof-of-concept exploit for CVE-2024-25170, demonstrating an access control bypass in Mezzanine CMS v6.0.0 via Host Header manipulation.

Automates deployment of misconfigured Azure/Entra ID tenants with configurable attack paths for adversary simulation, purple team exercises, and…

Repository contains psexec, which will help to exploit the forgotten pipe

Python-based scanner that checks Docker hosts for CVE-2024-41110 by detecting vulnerable Docker versions and AuthZ plugin usage.