
vuln-chm-hijack
Potential malicious code execution via CHM hijacking (CVE-2019-9896)

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

Morpheus - Automating Ettercap TCP/IP (MITM-hijacking Tool)

Credsleaker allows an attacker to craft a highly convincing credentials prompt using Windows Security, validate it against the DC and in turn leak it…

A simple script to generate a hidden url for social engineering.

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

Scripts to clone CA certificates for use in HTTPS client attacks.

A Windows Remote Administration Tool in Visual Basic with UNC paths

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

An XSS exploitation command-line interface and payload generator.

Phishing with a fake reCAPTCHA

Embed and hide any file in an HTML file

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)