
hacktricks
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Apple MacOS Screen Sharing Arbitrary File read/write -> RCE

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

Copy Fail - CVE-2026-31431 - Hardened C implementation for redteam and authorized penetration testing operations. ⚠️ Legal Notice: This tool is…

High Severity LPE vulnerability in Linux Kernel, with a CVS score of 7.8. An inverted check from user enables a process inside the container to break…

Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.

Exploit chain utilizing directory traversal and iOS restore to overwrite protected files.

Temporarily removes the root password using CVE-2026-31431

Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.

Exploit for CVE-2026-31431 that escalates privileges to root, with a detection mode and C implementation for portability.

Kerberos relaying and unconstrained delegation abuse toolkit

A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN

An unauthenticated privilege escalation problem tracked as CVE-2024-32444 (CVSS score: 9.8).

POC for CVE-2025-4404

A deep dive into two critical Sudo vulnerabilities (CVE‑2025‑32463 & CVE‑2025‑32462) that enable local privilege escalation across major Linux…

CVE-2021-34527 is a critical remote code execution and local privilege escalation vulnerability dubbed "PrintNightmare."

Exploit PoC for CVE-2023-20198