
internal-penetration-testing-project-using-Metasploit
Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB…

Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB…

This tool is used to find shell history leaking

Casper@shell:~# is an enhanced, more user-friendly version of p0wny shell with many new features.

Shell script to identify and exploit CVE-2023-43208, an unauthenticated remote code execution vulnerability in NextGen Mirth Connect before version…

Shell script to exploit CVE-2024-24919, enabling path traversal file retrieval from Check Point Security Gateways. Supports single IP and batch…

Shell script to exploit CVE-2020-13942, a remote code execution vulnerability in Apache Unomi, with pre-scanning via httpx or httprob.

Shell script to detect if the ssh binary is likely vulnerable to CVE-2024-3094, without requiring hexdump.

Morpheus - Automating Ettercap TCP/IP (MITM-hijacking Tool)

Specify targets and run sets of tools against them

An information gathering tool to collect git commit emails in version control host services

Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname

Utilize metasploit from a Kali Linux machine to exploit a well-known samba vulnerability (CVE-2007-2447). This is done in order to infiltrate a…

Full penetration test report against `IP` (Ubuntu VM). Attack chain: directory enumeration → backup file discovery → password cracking → CMS file…

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

First CTF successfully completed! This repo documents my walkthrough of TryHackMe's Simple CTF. It covers network reconnaissance (Nmap), web…

End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes,…

Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔…

Practical Penetration Testing Notes.