
exploitation-course
Offensive Software Exploitation Course

Offensive Software Exploitation Course

IDPS & SandBox & AntiVirus STEALTH KILLER. MorphAES is the world's first polymorphic shellcode engine, with metamorphic properties and capability to…

An exploit for CVE-2019-17026. It pops xcalc and was tested on Ubuntu (x64).

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Rust Weaponization for Red Team Engagements.

Linux Shared Library to Shellcode Loader

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

The FreeBSD ICMP buffer overflow, freebsd buffer overflow poc

CVE-2022-23093 FreeBSD Stack-Based Overflow

Manual exploit for Firefox RCE CVE-2016-9079 with customizable shellcode, served via HTTP for remote code execution on vulnerable Windows systems.

Python exploit for CVE-2022-3218 that generates a reverse TCP payload via msfvenom and delivers it over HTTP to a target Windows host.

Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a…

This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege…

Nano is a family of PHP web shells which are code golfed for stealth.

Combines AppDomain Manager injection with shellcode embedding in signed binaries to evade EDR/AV detection for red team payloads.

Proof of concept python script for regreSSHion exploit.