
ghostlock-s26
GhostLock (CVE-2026-43499) app for the Galaxy S26 series

GhostLock (CVE-2026-43499) app for the Galaxy S26 series

Tools and Techniques for Red Team / Penetration Testing

yet another sleep encryption thing. also used the default github repo name for this one.

Proof-of-concept demonstrating remote code execution via prompt injection in GitHub Copilot Chat, using a crafted Python file to trigger a…

OS Command Injection in Health Check → Remote Code Execution

A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.

MindsDB Path Traversal to RCE PoC

Authenticated Remote Command Execution in Gitlab via GitHub import

Python exploit for CVE-2020-1472 (Zerologon) that changes a domain controller's machine account password, enabling DCSync and full domain compromise.…

Exploit for CVE-2020-1472 (ZeroLogon) that changes a domain controller's machine account password, enabling DCSync and full domain compromise.…

Proof-of-concept exploit for CVE-2020-1472 (ZeroLogon) that changes the domain controller machine account password, enabling DCSync and full domain…

CVE-2023-23924 (Dompdf - RCE) PoC

Python exploit for vsftpd 2.3.4 - Backdoor Command Execution

Go-based exploit for CVE-2020-27955, achieving remote code execution via Git LFS on Windows across multiple development tools including Git, VS Code,…

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and…

Go-based exploit for CVE-2018-6574 using a shared library (attack.so) to demonstrate remote code execution vulnerability.

Windows RCE exploit for CVE-2020-27955 targeting git-lfs, affecting GitHub Desktop, VS Code, and other Git clients via crafted .bat/powershell…

Batch and PowerShell exploit for CVE-2020-27955, a Git-LFS remote code execution vulnerability affecting Git, GitHub Desktop, VS Code, and other…