
CVE-2020-8165
PoC for CVE-2020-8165

PoC for CVE-2020-8165

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Note: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

CVE-2018-6574 POC : golang 'go get' remote command execution during source code build

Chaining Havoc C2 SSRF with RCE to get reverse shell on Havoc C2 Server.

Remote command execution in Golang go get command allows an attacker to gain code execution on a system by installing a malicious library.

Proof-of-concept exploit demonstrating remote command execution in Go's `go get` via crafted cflags in a malicious third-party package.

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's Scheduled Cron Jobs feature

Python codes of my blog.

Executes position independent shellcode from an encrypted zip

A technique of hiding malicious shellcode via Shannon encoding.

Using CVE-2021-40449 to manual map kernel mode driver

LSTAR - CobaltStrike Translated to EN

Heap OOB write in MariaDB JSON_SCHEMA_VALID() → persistent privilege escalation (lab-assisted)

PHPMailer < 5.2.18 Remote Code Execution Exploit

A collection of selenium tests that might aid it takeover of a selenium node

A python implementation of CVE-2004-2271 targeting MiniShare 1.4.1.