
php-bypass-disable-functions
Demo project how to bypass the disable_functions security control of PHP on Linux

Demo project how to bypass the disable_functions security control of PHP on Linux

This repo contains all the work surrounding the development of the PoC for CVE-2024-48208, and how a simple OOB(Out-of-bound) read can result in jail…

My exploit for CVE-2024-48990. Full details of how I made this are on my blog.

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

How to spoof the command line when spawning a new process from C#.

A curated list of awesome OSCP resources

Windows protocol library, including SMB and RPC implementations, among others.

Local Windows kernel privilege escalation exploit for CVE-2018-8611 (KTM UAF) using write-what-where and increment primitives.

BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609,…

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

Kernel mode WinDbg extension and PoCs for token privilege investigation.

Detector + PoC for Linux page-cache write vulnerabilities: Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284/43500). Authorized security…

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image…

Implementation of Max Kellermann's exploit for CVE-2022-0847

Exploit chain utilizing directory traversal and iOS restore to overwrite protected files.

Using CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits