
striptls
proxy poc implementation of STARTTLS stripping attacks

proxy poc implementation of STARTTLS stripping attacks

Python script to scan and secure SSH configurations against the CVE-2024-6387 race condition vulnerability, with automated LoginGraceTime adjustment…

Python-based exploit for CVE-2026-24061, targeting a network service with customizable port and debug mode for security testing.

Crash macOS and iOS devices with one packet

ShellShock attack and exploit detector for Bro.

Nmap NSE script that queries the Vulners API to identify known vulnerabilities (CVEs) for detected network services, enhancing standard port scanning…

SSH User Enumerator in Python3, CVE-2018-15473, I updated the code of this exploit (https://www.exploit-db.com/exploits/45939) to work with python3…

Ansible playbook to detect and disable HTTP/HTTPS servers on Cisco IOS XE devices, mitigating CVE-2023-20198 vulnerability with automated…

Tool for mass testing ZeroLogon vulnerability CVE-2020-1472

Tool for mass testing ZeroLogon vulnerability CVE-2020-1472

Zeek script and Python utility to enrich network security monitoring logs with CVE identifiers for improved threat intelligence and vulnerability…

Network scanner that identifies hosts running OpenSSH versions vulnerable to CVE-2024-6387. Supports single IPs, CIDR ranges, CSV input, and…

Proof-of-concept exploit for CVE-2018-14847 allowing arbitrary file read of plaintext passwords from MikroTik RouterOS WinBox service, with TCP/IP…

A web version of the bash scripts wrote for Check Point CVE-2026-50751 and CVE-2026-50752. This uses a local server to scan and make changes using…

DHCP exploitation with DynoRoot (CVE-2018-1111)

Script to scan a list of hosts for CVE-2021-3156 (sudoedit privilege escalation) vulnerability, with configurable passwordless SSH connections for…

A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to…

Bro/Zeek script for detecting Apache Struts CVE-2017-5638 reconnaissance, compromise, and malware download tracking with automated IP extraction.