
wshlient
A simple tool to interact with web shells and command injection vulnerabilities

A simple tool to interact with web shells and command injection vulnerabilities

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

Simple dotnet Native AOT app that uses LibObjectFile to convert shellcode to ELF

Automated scanner and exploit for CVE-2025-34085, an unauthenticated RCE in the WordPress Simple File List plugin. Supports multi-target scanning,…

A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.

A very simple buffer overflow using CVE-2013-4730 against PCman's FTP server

A simple Docker lab and Exploit setup for CVE-2021-3156 - "Baron Samedit".

Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.

Simple exploit for Easy RM to MP3 Converter 2.7.3.700 on Windows 7 32b.

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Quickly debug shellcode extracted during malware analysis

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.

ImaegMagick Code Execution (CVE-2016-3714)

Authenticated remote code execution exploit for PlaySMS 1.4 via CSV phonebook upload. Provides single-command and interactive shell modes for…

Testing CVE-2022-22968

Create your malicious engine in seconds

Buffer Overflow in Seattle Lab Mail (SLmail) 5.5 - POP3