
stunner
Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC




Proof-of-concept exploit for CVE-2022-46364, an Apache CXF SSRF vulnerability enabling arbitrary file reads and internal network probing via crafted…

This repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an…

CVE-2012-1823 - PHP CGI Argument Injection Remote Code Execution (RCE)

Root-Level RCE via OS Command Injection in Ivanti Sentry

The VMWare Horizon Connection Server is often used as an internet-facing gateway to an organization’s virtual desktop environment (VDI). Until…

Security awareness training tool for authorized phishing simulations and internal IT audits

A critical Server-Side Template Injection (SSTI) vulnerability exists in the X-Trading Portal v1.4.2 dashboard metadata rendering engine. The flaw…

The code for personally reproducing the corresponding vulnerability

Technical Reference to multiple relay techniques

