
Penetration-Testing-Walkthrough-Hacksudo-Thor
Step-by-step black-box penetration test walkthrough exploiting Shellshock RCE (CVE-2014-6271) via Apache mod_cgi, chained with sudo misconfiguration…

Step-by-step black-box penetration test walkthrough exploiting Shellshock RCE (CVE-2014-6271) via Apache mod_cgi, chained with sudo misconfiguration…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

Generate SSRF proof-of-concept payloads for CVE-2021-22054 targeting VMware Workspace One UEM, with optional proxy and custom HTTP request support.

Built a custom Virtual Machine, running Ubuntu 18.04.1 and Webmin 1.810. Using CVE-2019-15107 to exploit a backdoor in the Linux machine

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

C# .NET assembly for post-exploitation reconnaissance on Windows hosts. Performs LDAP queries, DNS resolution, registry/disk enumeration, Windows…

Proof-of-concept exploit for unauthenticated remote code execution in Blocksy Companion Pro via double-extension file upload bypass.

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.

PoC exploit collection for CVE-2018-7600 Drupal RCE with multiple scripts targeting Drupal 7 and 8, including mass exploitation variants.

The perfect butler for pentesters, bug-bounty hunters and security researchers

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

Python exploit for Spring Framework Core RCE (CVE-2022-22965) with detection, batch scanning, and webshell deployment for JDK 9+ environments.

Exploit script for Apache HTTP Server 2.4.49/2.4.50 path traversal and remote code execution vulnerabilities (CVE-2021-41773, CVE-2021-42013).…

Batch detection and exploitation tool for Apache HTTP Server path traversal and RCE (CVE-2021-42013), with POC and EXP payloads for security testing.

Proof-of-concept exploit for CVE-2020-0688 targeting on-prem Microsoft Exchange. Includes scanning, cookie harvesting, payload generation via…

Remote Code Execution exploit for Apache servers. Affected versions: Apache 2.4.49, Apache 2.4.50