
hackingtool
All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Auto discover and exploit LAN raspberry pi's

Python proof-of-concept for detecting CVE-2023-27372 in SPIP CMS. Scans single or multiple URLs for the vulnerability and outputs results to terminal…

Blind XSS detection and exploitation platform with persistent sessions, reverse proxy, and automated information gathering for penetration testers…

Unveiled at DEF CON 20, NTLM Relaying to ALL THE THINGS!

iOS/macOS/Linux Remote Administration Tool

Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.

A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes

Get Keyboard,Mouse,ScreenShot,Microphone Inputs from Target Computer and Send to your Mail.

A blind XSS detection and XSS data capture framework

Proof-of-concept exploit for CVE-2022-42889 (Text4Shell) in Apache Commons Text, with manual and mass exploitation scripts using script, URL, and DNS…

Generates target specific word lists for Fuzzing with fuff

CVE-2023-33246 RocketMQ RCE Detect By Version and Exploit

Aimy Captcha-Less Form Guard Joomla Component PHP Object Injection RCE. clfgd XOR keystream recovery + unserialize(). CVSS 10.0 | CWE-502 |…

MCP server packaging a three-tier penetration-testing methodology: attack-surface reconnaissance, source-to-sink static analysis, and live finding…

Tools for investigating Log4j CVE-2021-44228

Self contained htaccess shells and attacks

Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info