
Zero-Day-Legacy
A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053

Generate wordlists using pattern logic and expressions.

This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE…


Project: vsFTPd 2.3.4 backdoor exploitation (CVE-2011-2523) on Metasploitable 2.

Full-lifecycle penetration test of a legacy Linux environment (Metasploitable 2) emulated on Apple Silicon. Demonstrating network reconnaissance, RCE…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.

Python script to execute CVE-2025-24071

The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks…

Generates targeted password wordlists by combining personal info, applying case/leet transforms, and scraping artist lyrics for enhanced cracking…

SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.

This project offers a straightforward solution for retrieving forgotten PDF passwords using Google Colab. With just five simple steps, it efficiently…

CVE-2023-23397 C# PoC

Rainbow table generation & lookup tools. Make Rainbow Tables Great Again!
