
URL_CHECKER
Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Research framework for collecting, analyzing, and tracking phishing sites. Uses headless Chromium to capture rendered HTML, screenshots, network…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Modular penetration testing framework integrating reconnaissance, exploitation, wireless attacks, web hacking, social engineering, OSINT,…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Ruby on Rails framework for managing and executing phishing campaigns, including email templates, landing pages, and campaign tracking.

Addressbar spoofing through blob URL (Firefox browser). An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by…

Proof-of-concept exploit for CVE-2022-25257: CSRF parameter injection in SAS Logon 9.4 enabling warning-message spoofing for phishing attacks.

Proof-of-concept exploit for CVE-2022-48429, a stored cross-site scripting vulnerability in JetBrains YouTrack dashboards enabling low-privileged…

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification…

Proof-of-concept scripts demonstrating reflected XSS in the Ultimate Classified Listings WordPress plugin and admin cookie theft via crafted payloads…

Automated fake-access-point toolkit for penetration testing, featuring captive portal phishing, WPA handshake capture, browser exploitation, and…

Proof-of-concept exploit for CVE-2024-42008, a Cross-Site Scripting vulnerability in RoundCube webmail. Delivers XSS payloads via contact forms to…

Rogue Wi-Fi access point framework for penetration testing, featuring MITM attacks, DNS spoofing, phishing portals, credential harvesting, and…

A PoC exploit for CVE-2022-0165 - Page Builder KingComposer WordPress Plugin - ID Parameter Validation Bypass

Combines evilginx3's MFA-bypassing reverse proxy with GoPhish's campaign management for automated phishing, smishing, and session token harvesting…

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中