
yolobox
Let your AI go full send. Your home directory stays home.

Let your AI go full send. Your home directory stays home.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).

A script used to create a whonix like gateway/workstation environment with docker containers.

Linux privilege escalation via LXD

CVE-2019-5736 POCs

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

Post-exploit a compromised etcd, gain persistence and remote shell to nodes.

Information about Kubernetes CVE-2020-8558, including proof of concept exploit.

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

LLM-first deception framework: "The honeypot that talks back!™"


一个功能强大的 Docker 远程 API 漏洞利用工具,用于 CVE-2025-9074 漏洞的安全研究和测试。

Exploit for CVE-2024-31989.
