
Lastenzug
Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

A high-fidelity x86_64 polymorphic mutation engine focused on instruction-level fragmentation and context preservation.

An exploit for CVE-2019-17026. It pops xcalc and was tested on Ubuntu (x64).

An automated exploit for CVE-2026-0073 (Android ADB TLS Auth Bypass). Features a built-in mDNS/Zeroconf scanner to instantly discover randomized…

Rust crate for ghost-frame call-stack spoofing, runtime indirect syscalls, and APC injection on Windows x64. Provides SSN resolution, JIT stub…

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Foxit Reader version 9.0.1.1049 Use After Free with ASLR and DEP bypass on heap

Proof-of-concept exploit for CVE-2021-21300, demonstrating remote code execution via malicious git repository cloning with symlink and filter abuse…

Python script to exploit PlaySMS before 1.4.3

Safari 1day RCE Exploit

Python-based exploit development framework with payloads, encoders, and connect-back servers, focused on MIPS CPU architecture but designed for…

Proof-of-concept PHP 8 sandbox escape exploiting a use-after-free bug to bypass disable_functions and execute system commands on Unix-like systems.

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

End-to-end exploitation lab for CVE-2025-5548 (FreeFloat FTP Server stack buffer overflow). Includes static analysis with IDA/Ghidra, binary fuzzing,…

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

Automated exploit for CVE-2024-23741 targeting Hyper on macOS. Validates vulnerability and injects code to spawn a remote shell via RunAsNode and…

Cmulator is ( x86 - x64 ) Scriptable Reverse Engineering Sandbox Emulator for shellcode and PE binaries . Based on Unicorn & Zydis Engine &…

Exploit script for CVE-2020-24186 in WordPress that uploads a camouflaged PHP webshell and provides interactive or reverse shell access with optional…