
wifiphisher
Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

Social engineering attack vector and exploitation framework for hijacking user sessions via QR code login, targeting web applications like WhatsApp,…

evilginx3 + gophish

Hacking tools pack & backdoors generator.

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!

Serverless AITM Simulation Framework for Entra ID and M365

Addressbar spoofing through blob URL (Firefox browser). An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by…


Public advisory & PoC for CVE-2026-26897 — Deep Link Bypass in EcoOnline EHS Android (com.airsweb.v10), fixed in 0.2.500

HostHeaderInjection-Askey

The plugin does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone…

In LetterPress plugin <= 1.2.1 is vulnerable to Cookie Stealing Vulnerability. An attacker can able to steal the cookies by injecting the JavaScript…

This is a reproduction of PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF) vulnerability