
CVE-2023-23397
Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted…

Python script that brute-forces Ghost CMS credentials, then checks for CVE-2024-23724 and generates an SVG exploit payload for confirmed vulnerable…


Automated Linux evil maid attack

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

Collection of VBA macro published in our twitter / blog

A credential extraction BOF for Veeam Backup and Replication and Veeam One

Chalumeau is automated,extendable and customizable credential dumping tool based on powershell and python.

A little tool to play with Kerberos.

CVE-2023-23397 PoC

cve-2016-16113

CVE-2023-6875 exploit written for Xakep.Ru

Strapi Framework, 3.0.0-beta.17.4

Rapid psexec-style attack tool using Samba for remote command execution, credential dumping, and lateral movement across Windows networks with hash…

Modular Python3 attack framework for automating exploitation of SIEM platforms (Splunk, Graylog, OSSIM, QRadar, McAfee) via credential theft, payload…