
blackbox-pentesting-infsecos
Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Grafana Unauthorized arbitrary file reading vulnerability

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras…

CrackerJack / Hashcat Web Interface / Context Information Security

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core

Automates SQL injection exploitation with SQLMAP, crawls for vulnerabilities, extracts database credentials, finds admin login pages, and cracks…

Password cracking utility

There are many cheat sheets out there, but this is mine.

POC - CVE-2024–4956 - Nexus Repository Manager 3 Unauthenticated Path Traversal

CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)

Proof of Concept for WatchGuard Authenticated Arbitrary File Read (CVE-2022-31749)

Python utility for automating CVE-2024-4956 path traversal exploitation with mass file extraction, plus custom Hashcat module for cracking Apache…

Python exploit for CVE-2026-89012, a Dolibarr SQL filter denylist bypass that uses a blind-boolean oracle to extract password hashes and API keys via…

The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.