
Pingpon-Exploit
Exploit for Mass Remote Code Execution on GPON home routers (CVE-2018-10562) obtained from Shodan.

Exploit for Mass Remote Code Execution on GPON home routers (CVE-2018-10562) obtained from Shodan.


Uses Shodan API to pull down C2 servers to run known exploits on them.


Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

Generate wordlists of Danish phone numbers by area and/or usage (Mobile, landline etc.) Useful for password cracking or fuzzing Danish targets.

A proof of concept demonstrating how to use the Hinge dating app as a C2.

Analysis of state-sponsored WhatsApp phishing infrastructure with real-time QR hijacking and device surveillance

PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

a Fedora remix focused on pentesting and purple hat tooling

Bash tool that routes all system network traffic through Tor for IP anonymization, with manual/automatic IP rotation and current IP/location display.

Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API.

Multithreaded reverse IP lookup tool for discovering domains hosted on the same IP address.

Shodan-based scanner that discovers FortiGate SSL VPN devices and tests them for CVE-2024-21762 vulnerability, displaying organization and country…

PoC, Hunting React2Shell about CVE-2025-55182

CVE-2022-26134, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server…

crawls the website and finds broken social media links that can be hijacked