
XSSTracer
A small python script to check for Cross-Site Tracing (XST)

A small python script to check for Cross-Site Tracing (XST)

Python script that automatically patches GitHub Actions workflow files to replace deprecated and insecure ::set-env and ::add-path commands with the…

Proof-of-concept exploit for XenForo CVE-2026-73318, an authorization bypass allowing ACP administrators to trigger site-wide policy re-agreement.…

This Python script exploits a critical mass assignment vulnerability in Camaleon CMS version 2.9.0, allowing any registered user to escalate their…

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Lightweight Python script to detect CVE-2017-9798 in shared hosting environments by scanning for vulnerable .htaccess files, exiting with code 1 if…

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Python-based web security scanner that analyzes HTTP headers, SSL/TLS, DNS records, and common misconfigurations to generate a scored security report…

IngressNightmare (CVE-2025-1974)

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

Docker-based lab for Apache CVE-2021-41773 path traversal and RCE exploitation with Python exploit script, demonstrating vulnerability analysis and…

log4j mitigation work

This script is a tool to recursively download the contents of the '.git' directory from a website. Using Python and libraries like 'requests' and…

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

Local Linux enumeration script that identifies privilege escalation vectors including misconfigurations, world-writable files, clear-text passwords,…

Exploitation script for exposed Java Debug Wire Protocol (JDWP) services, enabling pentesters to inject Java code and execute arbitrary OS commands…

Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer/ CIS Benchmark

Mitigate log4shell (CVE-2021-44228) vulnerability attacks using Nginx LUA script