
krackattacks-scripts
Scripts to verify WPA2 clients and APs for KRACK key reinstallation vulnerabilities using modified hostapd and monitor-mode frame replay.

Scripts to verify WPA2 clients and APs for KRACK key reinstallation vulnerabilities using modified hostapd and monitor-mode frame replay.

SensePost's modified hostapd for wifi attacks.

A nodemcu powered wifi spammer

Exploit Windows server 2019 vulnerable to Zerologon with Garble, Chisel, wp-file-manager vulnerability (have video demo)

Python-based exploit generator for CVE-2023-38831 WinRAR vulnerability. Creates malicious RAR archives with bait files (PDF, images) and payload…

An evil RMI server that can launch an arbitrary command. May be useful for CVE-2021-44228

Python-based exploit generator for CVE-2023-38831 (WinRAR remote code execution). Creates malicious RAR archives with bait files and payload scripts…

CVE-2019-5010 Exploit PoC - Python Denial of Service via Malformed X.509v3 Extension


Don't be evil.

Proof of Concept for CVE-2021-1585: Cisco ASA Device Manager RCE

Proof-of-concept exploit for CVE-2025-1562, a WordPress plugin activation vulnerability allowing remote code execution via crafted REST API requests.

Explore CVE-2022-41741 with the Evil MP4 repository. It offers educational PoCs,and documentation on securing nginx against MP4 file vulnerabilities.…

Spring Cloud Gateway < 3.0.7 & < 3.1.1 Code Injection (RCE)

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

CVE-2023-38831 winrar exploit generator

Python exploit for Moodle Evil Teacher vulnerability (CVE-2018-1133) enabling authenticated remote command execution with proxy support.

Multi-purpose WiFi penetration testing toolkit for M5Stack devices. Performs network scanning, evil-twin attacks, deauthentication, captive portal…