
oauthseeker
A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Read more at Medium

Proof-of-concept exploit for a cross-site scripting (XSS) vulnerability in Microsoft Outlook for iOS, enabling email-based spoofing attacks and…

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

a CLI for ephemeral penetration testing

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.