
CVE-2021-4034
Shell script that exploits CVE-2021-4034 (PwnKit) for local privilege escalation, intended for CTF use.

Shell script that exploits CVE-2021-4034 (PwnKit) for local privilege escalation, intended for CTF use.

Shell script to detect and mitigate CVE-2022-1679, a use-after-free vulnerability in the Linux kernel's ath9k wireless driver that allows local…

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing attack to inject a sudo user and gain root shell on vulnerable…

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing race condition to create a sudo user and gain root shell on…

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

Weaponized web shell

Yet Another PHP Shell - The most complete PHP reverse shell

PostShell - Post Exploitation Bind/Backconnect Shell

Local privilege escalation exploit for CVE-2021-4034 in pkexec, providing a proof-of-concept that drops a root shell on vulnerable systems.

Proof of Concept exploits for CVE-2025-34322 and CVE-2025-34323 in Nagios Log Server

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

Shell implementation of CVE-2021-4034, a local privilege escalation exploit for pkexec, enabling privilege escalation on vulnerable Linux systems.

Python exploit for CVE-2020-14008 in ManageEngine Applications Manager delivering a SYSTEM-level reverse shell via authenticated remote code…

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Hacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn a root shell. (and attempts to restore the damaged binary as well)

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

Exploitations scripts for CVE-2023-42791 and CVE-2024-23666.