
vm-homelab-log4shell-assessment
Full-lifecycle vulnerability management on a live Log4Shell (CVE-2021-44228) target — scan, manual exploitation, network detection, and remediation…

Full-lifecycle vulnerability management on a live Log4Shell (CVE-2021-44228) target — scan, manual exploitation, network detection, and remediation…

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

Automated man-in-the-middle attack tool.

Interactive demo of CVE-2022-45059 Varnish Cache request smuggling vulnerability. Includes Spring Boot web app, vulnerable proxy, automated victim…

Proof-of-concept RCE exploit for CVE-2022-1388 (F5 BIG-IP iControl REST) with interactive shell, command execution, and automated PCAP export for…

PoC exploit and tooling for CVE-2021-26258, including a custom storage file packer/unpacker and a MITM web server to deliver malicious updates to…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Multi-VLAN enterprise network vulnerability assessment using Nessus, OWASP ZAP, and Wireshark. Confirms Stored XSS on WebGoat and EternalBlue…

Desktop HTTP/HTTPS interception proxy with live traffic capture, request replay, HAR import/export, and a rules engine for delaying, overriding, or…

Browser extension for HTTP/WebSocket traffic capture, interception, modification, replay, and fuzzing with AI-assisted analysis and rule-based…

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

Automated MITM suite leveraging Ettercap for ARP poisoning, traffic sniffing, credential harvesting, payload injection, and network reconnaissance…

ARP spoofing and MITM tool for intercepting HTTP/FTP/IMAP/POP3/IRC traffic, injecting HTML/JS, DNS spoofing, and WiFi deauth jamming on local…

Proof-of-concept for Log4Shell (CVE-2021-44228) demonstrating remote code execution via JNDI injection, including vulnerable server setup, exploit…