
ctf-cve-2019-11043
Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

A tool that allows you to search for vulnerable android devices across the world and exploit them.


CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Dumping App Bound Protected Credentials & Cookies Without Privileges.

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

Blog post exploring macOS App Sandbox, entitlements via codesign, and sandbox escape techniques using launchd, LaunchAgents, and quarantine…

A command-line utility to exploit Android Zygote injection (CVE-2024-31317)

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Leverage WindowsApp createdump tool to obtain an lsass dump

ExtensionHijack

Notion as a platform for offensive operations