
BridgeHead
Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.

Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

Python exploit script for CVE-2020-5902 (F5 BIG-IP) supporting local file read and remote code execution via crafted HTTP requests.

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

Quicky serve files over http or https using flask.

Một tập lệnh Python để DDOS một trang web bằng phương pháp HTTP Flood, một trang web bình thường chỉ cần 5s để sập hoàn toàn!

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

confluence CVE-2023-22527 漏洞利用工具,支持冰蝎/哥斯拉内存马注入,支持设置 http 代理

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected…

Unauthenticated RCE Flaw in Rejetto HTTP File Server (CVE-2024-23692)

Proof-of-concept exploit for SonicWall SonicOS stack-based buffer overflows (CVE-2022-22274, CVE-2023-0656) that tests and triggers crashes via…

Proof-of-concept exploit for Apache HTTP Server path traversal vulnerability CVE-2021-41773, with Docker setup and detailed vulnerability analysis.

Perl-based exploit for CVE-2014-7236 targeting TWiki code execution vulnerability. Enables remote command injection on vulnerable TWiki installations…

PoC and exploit for CVE-2022-40684, an authentication bypass in Fortinet FortiOS, FortiProxy, and FortiSwitchManager management interfaces, enabling…

Python exploit for CVE-2025-64446 targeting FortiWeb WAF, enabling unauthorized user creation and privilege escalation through a crafted HTTP request.

Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write, Remote Code Execution and SMB…

Verified PoC and analysis for CVE-2026-21962, an access-control bypass in Oracle HTTP Server/WebLogic Proxy Plug-in via URI normalization…

SOCKS5-to-HTTP proxy bridge that tunnels arbitrary TCP streams (SSH, SMTP, TLS) through standard HTTP requests, enabling network traffic obfuscation…