
OffensiveNim
My experiments in weaponizing Nim (https://nim-lang.org/)

My experiments in weaponizing Nim (https://nim-lang.org/)

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

Six Degrees of Domain Admin

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk


Persistence by writing/reading shellcode from Event Log

A fully implemented kernel exploit for the PS4 on 5.05FW

pgAdmin 4 Import/Export RCE (CVE-2026-17566) PoC - TO PROGRAM injection via backslash-escape mismatch

Python PoC exploiting CVE-2024-2044 in pgAdmin 4 (<=8.3) via authenticated path traversal and unsafe pickle deserialization to achieve remote code…