
WSS
Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…

Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…


A collection of custom security tools for quick needs.

Proof-of-concept exploit for CVE-2021-36394 in Moodle, enabling admin password takeover and remote code execution via custom PHP functions.

CVE-2023-5359 scanner for W3 Total Cache cleartext storage vulnerability. Detects exposed credentials (API keys, OAuth tokens) in publicly accessible…

Proof-of-concept for CVE-2022-45599: PHP type juggling vulnerability in Aztech WMB250AC router login.php allowing admin authentication bypass via…

ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade, convert, dissect and shuck authentication token based…

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.


Free advanced and modern Windows botnet with a nice and secure PHP panel developed using VB.NET.

complex webshell manager, quasi-http botnet.

php-cli vulnerability scanner

[NEW] : Mega Bot ☣ Scanner & Auto Exploiter