
nasm_linux_x86_64_pure_sharedlib
NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

This repo stores necessary files for the analysis blog which will come soon

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

Nano is a family of PHP web shells which are code golfed for stealth.

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

complex webshell manager, quasi-http botnet.

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Python exploit for CVE-2019-11447 that uploads a PHP reverse shell to CuteNews 2.1.2, enabling remote command execution on vulnerable web…

WAMpage - A WebOS root LPE exploit chain (CVE-2022-23731)

Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a…

CVE-2019-9729. Transferred from https://github.com/DoubleLabyrinth/SdoKeyCrypt-sys-local-privilege-elevation

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

WonderCMS v3.2.0 - v3.4.2 XSS to RCE exploit

Scripts to analyze conflicker worm which exploits famous netapi vulnerability (CVE-2008-4250) i.e MS08-067

Testing CVE-2022-22968