
1day-archive
Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

A collection of awesome penetration testing resources, tools and other shiny things

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Curated study guide for OSCE3 certifications (OSWE, OSEP, OSED, OSEE) covering web exploitation, post-exploitation, payload development, lab setups,…

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

Exploit chain for Safari + macOS exploiting JIT type confusion, launchd sandbox escape, and XNU IPC MitM for kernel code execution.

Intentionally vulnerable open-world MMORPG server for practicing binary exploitation, reverse engineering, network protocol analysis, and web…

An strace-like program for the Windows 'native' API

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

Exploit for Sagemcom F@ST 3890 cable modem implementing Cable Haunt vulnerability to achieve remote code execution via WebSocket-based buffer…

Public repository for improvements to the EXTRABACON exploit

Maps attack surface of GWT applications by extracting obfuscated RPC endpoints and generating serialized request payloads for security testing.

Intentionally vulnerable Android banking app for practicing mobile security testing. Covers OWASP Mobile Top 10 with hardcoded credentials, insecure…

MAPS cloud scanner and response parser for Microsoft Defender research.

Proof-of-concept exploit for CVE-2024-21633 demonstrating remote code execution in MobSF by abusing apktool arbitrary file write to overwrite a…