
LinPwn
Interactive post-exploitation tool for Linux privilege escalation, enumeration, file exfiltration, and credential harvesting via reverse shell.

Interactive post-exploitation tool for Linux privilege escalation, enumeration, file exfiltration, and credential harvesting via reverse shell.

Advanced Recon tool for Bug Bounty and Pentesting

Dump the saved wifi passwords for windows using regular expressions and python 3

Find credentials in screenshots, save them to your secret manager, and irreversibly redact them from the image — local, offline, OCR-based.

Unauthenticated time-based blind SQL injection exploit for NotificationX WordPress plugin (CVE-2024-1698) that extracts admin username and password…

Crestron AirMedia AM-100 Traversal and Hashdump Metasploit Modules

A technical case study and exploitation analysis of the Authentication Bypass vulnerability in TP-Link TL-WR840N firmware (CVE-2018-12633).

This exploit targets an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9 (CVE-2019-9053). It uses a time-based blind SQL…

Exploit for CVE-2025-44203 targeting a race condition in HotelDruid 3.0.0/3.0.7 that leaks admin credentials and causes denial of service. Includes a…

Sniffs sensitive data from interface or pcap

Automatically exported from code.google.com/p/fern-wifi-cracker

PowerShell Script to Dump Windows Credentials from the Credential Manager

Grafana Unauthorized arbitrary file reading vulnerability


Common password pattern generator using strings list

Password list generator for password spraying - prebaked with goodies

CVE-2013-4786 Go exploitation tool

POC - CVE-2024–4956 - Nexus Repository Manager 3 Unauthenticated Path Traversal