
AutoSploit
Automated Mass Exploiter

Automated Mass Exploiter

Proof-of-concept exploit for Apache HTTP Server path traversal vulnerability CVE-2021-41773, with Docker setup and detailed vulnerability analysis.

Scan .onion hidden services with nmap using Tor, proxychains and dnsmasq in a minimal alpine Docker container.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

Automated container orchestration tool for Browser-in-the-Browser (BITB) phishing attacks, enabling red teams to scale multi-target infrastructure…

LLM-first deception framework: "The honeypot that talks back!™"


PoC for CVE-2024-21626: runc leaks an internal fd referencing the host CWD before pivot_root, enabling container escape by setting process.cwd to…

A critical Remote Code Execution (RCE) vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to…

PoC exploit for insecure permissions in Contour v1.28.3 that retrieves a Kubernetes service account token and accesses the cluster API, demonstrating…

End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common…

Linux privilege escalation via LXD

eBPF-based stealth container that hides processes, sockets, eBPF objects, and audit logs from system monitoring tools, enabling covert…

CVE-2019-5736 POCs

Information about Kubernetes CVE-2020-8558, including proof of concept exploit.

ingress-nginx admission controller RCE escalation PoC