
Winrar-Exploit-CVE-2023-38831
C# utility demonstrating CVE-2023-38831 archive-structure exploitation technique for WinRAR versions below 6.23. Builds proof-of-concept binaries for…

C# utility demonstrating CVE-2023-38831 archive-structure exploitation technique for WinRAR versions below 6.23. Builds proof-of-concept binaries for…

Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking,…

This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a…

WordPress Munk Sites plugin <= 1.0.7 - CSRF to Arbitrary Plugin Installation vulnerability

Public writeup for CVE-2025-55996 (Viber Desktop HTML Injection)

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance


Demonstrates capturing NTLM hashes via Responder and executing phishing emails exploiting CVE-2024-21413 to compromise systems.

Demonstrates an IDN homograph attack in Chromium extensions to spoof URLs, aiding in deception attacks by coercing victims into granting permissions…

CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the…

Send Mail Anonymously with this Script

📱 🐟 An app to remote control SocialFish.

A PowerShell based utility for the creation of malicious Office macro documents.

Digital Methods Initiative - Twitter Capture and Analysis Toolset

internet monitoring osint telegram bot for windows

Real-time phishing platform that bypasses 2FA via a live noVNC browser session, capturing cookies, saved passwords, browsing history, and downloaded…

The goal of Axiom is to provide a completely anonymous, decentralized, and censorship-resistant social media platform. To make this possible, the…

Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess