
cve-2017-7269-tool
CVE-2017-7269 to webshell or shellcode loader

CVE-2017-7269 to webshell or shellcode loader

CVE-2022-25845 (fastjson 1.2.80) exploit for Spring environments with step-by-step PoC, file read, and arbitrary file write via Jackson/commons-io…

This is a concept poc of command and control server implemented over blockchain

Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code…

Cisco ASA Software and ASDM Security Research

CVE-2021-26084 Remote Code Execution on Confluence Servers

ImaegMagick Code Execution (CVE-2016-3714)

Proof-of-concept code for Android APEX key reuse vulnerability

Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.

PoC and analysis for CVE-2022-26809, a Windows RPC runtime integer overflow vulnerability. Includes trigger scripts using PetitPotam-style UNC path…

Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)

Pre-auth RCE proof-of-concept for Apache OFBiz CVE-2023-49070, exploiting XML-RPC Java deserialization to achieve remote code execution on vulnerable…

Proof-of-concept exploit for CVE-2024-26218, demonstrating a specific vulnerability for security research and testing.

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

Cobalt Strike UDRL that performs advanced module stomping using VEH to intercept calls, unmap modules during sleep, and remap fresh modules to evade…

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2

Hacking Artifactory with server side template injection

Proof-of-concept exploit for CVE-2026-46243, leveraging a fake NSS library and namespace manipulation to escalate privileges via cifs.upcall.