
quasibot
complex webshell manager, quasi-http botnet.

complex webshell manager, quasi-http botnet.

Kyocera cred dumper based on CVE-2022-1026

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

Exploit for CVE-2014-0195

Bludit 3.9.2 - bruteforce bypass - CVE-2019-17240

CVE-2025-51482 POC, Dump Credentials From zm.Users

Automated exploit for Rocket.Chat NoSQL injection (CVE-2021-22911) that leaks password reset tokens and performs unauthenticated account takeover.

ZenoMinder Blind SQL Injection PoC

Dracos Linux ( www.dracos-linux.org ) is the Linux operating system from Indonesian

Highly configurable script for dictionary/spray attacks against online web applications.

a very fast brute force webshell password tool

WPScan rewritten in Python + some WPSeku ideas