
Exploits_and_Advisories
Repository that tracks public exploits, vulnerabilities and advisories that I [co-]discovered or [co-]authored.

Repository that tracks public exploits, vulnerabilities and advisories that I [co-]discovered or [co-]authored.

Real world and CTFs exploiting web/binary POCs.

Deploys realistic virtual SCADA/ICS testbeds with IEC 60870-5-104 and OPC-UA nodes, enabling attack simulations, legitimate packet generation, and…

BOF (Boiboite Opener Framework) is a testing framework for industrial protocols implementations and devices.

Self-hosted network discovery and search engine with continuous port scanning, deep protocol probing across ~100 services, local CVE matching, and…

Working exploit for Phoenix Contact CHARX SEC-3100 using Scapy raw Ethernet packets to trigger vulnerabilities and obtain an interactive connect-back…

Description and exploit of CVE-2023-33831 affecting FUXA web-based Process Visualization (SCADA/HMI/Dashboard) software.

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

Analyzing and Reproducing the Command Injection Vulnerability (CVE-2023-0861) in NetModule Routers

Detection-engineering reference mapping Windows, cloud, container, identity, and ICS attack classes to Sigma rules, trust-boundary models, BYOVD…

Proof-of-concept reproducing CVE-2021-22681's hardcoded-key flaw and validating a per-device mutual TLS/CRL fix over simulated EtherNet/IP, with IEC…

Technical vulnerability analysis and CVE briefing for CVE-2026-9645 affecting ScadaBR.

Proof of Concept (PoC) for CVE: 2017-16744 and 2017-16748

DoS exploit for CVE-2015-5374 targeting Siemens SIPROTEC 4 and Compact EN100 Ethernet modules via a crafted UDP packet to port 50000, with an…

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

Public technical advisory and reproduction evidence for CVE-2026-52134 affecting GOOSE replay handling in libiec61850 v1.6.

Python exploit for CVE-2025-69985 targeting FUXA SCADA software. Sends crafted JSON payload to /api/runscript endpoint to bypass authentication and…

Active Scanning and Information Gathering in ICS/SCADA Networks using Network Mapper (NMAP) (Turkish)