
MegaQuagga_Pentesting_Report
Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…


Webshell, Virtual Private Server (VPS) and cPanel Database



Một tập lệnh Python để DDOS một trang web bằng phương pháp nhiều phương pháp HTTP Flood, một trang web bình thường chỉ cần 5s để sập hoàn toàn!

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

Exploits targeting vBulletin.


PoC for CVE-2025-8110: Authenticated RCE in Gogs via symlink bypass in PutContents API

load-scripts.php file, which purpose is to retrieve several JavaScript packages through one single request.

Authenticated remote code execution exploit for Windows Admin Center via WinREST/PowerShell invokeCommand; takes credentials and runs arbitrary…

a CLI for ephemeral penetration testing

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or…