
goshs
Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

Bash script to check if a domain or list of domains can be spoofed based in DMARC records

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Spoof file icons and extensions in Windows

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…


A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats.…

The Browser Exploitation Framework Project

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

Microweber version 2.0.4 vulnerable to "Uploading Malicious Files"

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

📡 A python program to create a fake AP and sniff data.

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

Proof-of-concept exploit for CVE-2017-5223 demonstrating arbitrary file read via PHPMailer's attachment and email content injection.

ConcreteCMS v.9.2.1 is affected by Arbitrary File Upload vulnerability that allows Cross-Site Scriting (XSS) Stored.

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC