
poisontap
Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where…

CVE-2017-1635 PoC code

exim use after free exploit and detection

SquirrellyJS mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer


PeekABoo tool can be used during internal penetration testing when a user needs to enable Remote Desktop on the targeted machine. It uses PowerShell…