
CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below
Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

Windows keystroke logger with local file logging and remote exfiltration via email, FTP, and Google Forms, plus optional startup persistence for…

A credential extraction BOF for Veeam Backup and Replication and Veeam One

Automated credential dumping tool with custom PowerShell payloads, in-memory execution, Mimikatz parsing, ticket dumping, and web-based dashboard for…

Proof-of-concept exploit for CVE-2025-60787, an OS command injection in motionEye v0.43.1b4, enabling remote code execution via crafted…

Proof-of-concept exploit for CVE-2020-7378 chaining predictable password reset token generation with blind XXE to gain admin access and exfiltrate…

Automated Linux evil maid attack tool that backdoors initrd images to drop a meterpreter shell and exfiltrate full-disk encryption passwords upon…

Collection of VBA macro published in our twitter / blog

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell…