
EvilAbigail
Automated Linux evil maid attack

Automated Linux evil maid attack

Collection of VBA macro published in our twitter / blog

Chalumeau is automated,extendable and customizable credential dumping tool based on powershell and python.

A credential extraction BOF for Veeam Backup and Replication and Veeam One

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

Proof-of-concept exploit for CVE-2020-7378 chaining predictable password reset token generation with blind XXE to gain admin access and exfiltrate…

Proof-of-concept exploit for CVE-2025-60787, an OS command injection in motionEye v0.43.1b4, enabling remote code execution via crafted…

RomBuster is a router exploitation tool that allows to disclosure network router admin password.

The LAZY script will make your life easier, and of course faster.

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted…

Python script that brute-forces Ghost CMS credentials, then checks for CVE-2024-23724 and generates an SVG exploit payload for confirmed vulnerable…

Rapid psexec-style attack tool using Samba for remote command execution, credential dumping, and lateral movement across Windows networks with hash…

Modular Python3 attack framework for automating exploitation of SIEM platforms (Splunk, Graylog, OSSIM, QRadar, McAfee) via credential theft, payload…

CVE-2004-1769 // Mass cPanel Reset password


tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含