
Http-Asynchronous-Reverse-Shell
[POC] Asynchronous reverse shell using the HTTP protocol.

[POC] Asynchronous reverse shell using the HTTP protocol.

Proof-of-concept exploit for CVE-2021-41773, demonstrating path traversal and remote code execution on Apache HTTP Server 2.4.49 with a reverse shell…

HTTP Server serving obfuscated Powershell Scripts/Payloads

Proof-of-concept exploit for CVE-2024-10793 targeting WordPress wp-security-audit-log plugin. Demonstrates account takeover, privileged user…

Exploit PoC and Nuclei template for CVE-2026-21962, a critical unauthenticated remote code execution in Oracle HTTP Server and WebLogic Proxy…

Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC

Python exploit script for CVE-2022-25581 (ClassCMS 2.4 arbitrary file download) that automates login, CSRF token extraction, malicious zip upload…

Python / C# Unmanaged PowerShell based RAT

A malicious LDAP server for JNDI injection attacks

Private Nginx Rift ASLR lab, exploit chain, and demo recordings

Explore RootSec's DDOS Archive, featuring top-tier scanners, powerful botnets (Mirai & QBot) and other variants, high-impact exploits, advanced…

Adversary Emulation Framework

Go-based proof-of-concept exploit for CVE-2026-23918 targeting a double-free vulnerability in Apache httpd mod_http2, enabling pre-auth remote code…

Generates a malicious Microsoft Word document exploiting the MS-MSDT 'Follina' vulnerability to execute arbitrary commands or stage payloads via an…

HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907

Proof-of-concept exploit for CVE-2022-39197, enabling remote code execution against CobaltStrike <= 4.7.1 via malicious SVG payload served over HTTP.

Generates workable JNDI injection links and deserialization payloads with 80+ gadgets, supporting RMI, LDAP, and HTTP servers for automated…

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles