
claude-code-backdoor
Backdooring Claude Code via hooks in settings.json. Authorized use only!

Backdooring Claude Code via hooks in settings.json. Authorized use only!


Writeup on CVE-2020-28328: SuiteCRM Log File Remote Code Execution plus some bonus Cross-Site Scripting

Discovering CVE-2025-22381: Host Header Injection in the Aggie Open-Source Project

WordPress Munk Sites plugin <= 1.0.7 - CSRF to Arbitrary Plugin Installation vulnerability

Demonstrates capturing NTLM hashes via Responder and executing phishing emails exploiting CVE-2024-21413 to compromise systems.

Hunt down social media accounts by username across social networks

Grab cam shots & GPS location from target's phone front camera or PC webcam just sending a link.

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

A list of cyber-chef recipes and curated links

Send phishing messages and attachments to Microsoft Teams users

FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule…

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…

Targeted evil twin attacks against WPA2-Enterprise networks. Indirect wireless pivots using hostile portal attacks.

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

Ruby on Rails Phishing Framework