
peeko
peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

The detection of internal security controls at a company

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

Test for CVE-2000-0649, and return an IP address if vulnerable

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

Technical Reference to multiple relay techniques

PoC and internal port brute-forcer for CVE-2023-27163


The VMWare Horizon Connection Server is often used as an internet-facing gateway to an organization’s virtual desktop environment (VDI). Until…


Atlassian Jira XSS attack via Server Side Request Forgery (SSRF).

API Scraper Agent for Web API's

This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where…

Unauthenticated Arbitrary File Read via Absolute Path

Microsoft Network Service Fingerprinting Tool

CVE-2022-23779: Internal Hostname Disclosure Vulnerability