
shellerator
Simple CLI tool for the generation of bind and reverse shells in multiple languages

Simple CLI tool for the generation of bind and reverse shells in multiple languages

Pop shells like a master.

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Java-based proof-of-concept exploit for CVE-2021-44228 (Log4Shell) enabling remote command execution, OS information gathering, and arbitrary…

This is my implementation of JSRat.ps1 in Python so you can now run the attack server from any OS instead of being limited to a Windows OS with…

Automated proof-of-concept exploit for CVE-2023-4220 in Chamilo LMS, enabling arbitrary file upload and remote code execution via unauthenticated…

An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution

The LAZY script will make your life easier, and of course faster.

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

Self-developed tools for Lateral Movement/Code Execution

Simple exploit for Wing FTP Server RCE (CVE-2025-47812) to run commands and get a reverse shell. For educational use only.

Python PoC for CVE-2025-47812, unauthenticated RCE in Wing FTP Server <= 7.4.3 via NULL-byte Lua injection into session files

CVE-2016-5195 dirtycow by timwr automated multi file patch tool

A Netcat-style backdoor for pentesting and pentest exercises

Manual exploit for CVE-2020-9496, an unauthenticated Java deserialization RCE in Apache OFBiz XML-RPC, with step-by-step instructions for payload…

Nginx CVE-2019-20372 PoC, Unauthenticated File Upload Exploit

Exploit PoC for CVE-2025-53770 enabling webshell upload to SharePoint, ValidationKey extraction, signed ViewState generation, and remote code…

POC for CVE-2023-4220 - Chamilo LMS Unauthenticated Big Upload File Remote Code Execution