
CVE-2016-5195
Educational implementation of the Dirty COW (CVE-2016-5195) privilege escalation exploit, including race condition payload and SUID-based root shell…

Educational implementation of the Dirty COW (CVE-2016-5195) privilege escalation exploit, including race condition payload and SUID-based root shell…

Proof-of-concept denial-of-service tool that enforces Diffie-Hellman ephemeral key exchange over TLS and SSH to saturate server CPU, implementing…

Proof-of-concept denial-of-service tool that exploits the DHEat attack (CVE-2002-20001) by enforcing Diffie-Hellman key exchange against TLS and SSH…

Python PoC for CVE-2026-11118 demonstrating HTTP/2 Rapid Reset DDoS via RST_STREAM resource exhaustion; includes vulnerable server simulator and…

PoC for HTTP/2 Rapid Reset DDoS Vulnerability - CVE-2023-44487

Replicable Blueprint for advanced DDoS Purple Teaming, engineered for the threat landscape. It integrates a Red Elite Teaming offensive…

CVE-2025-25063 MadeYouReset HTTP/2 DDoS

This document describes a Denial of Service (DoS) vulnerability found in certain versions of MikroTik RouterOS. The vulnerability is due to…

Scanner and attack suite for hosts that forward unauthenticated packets via IPIP and GRE protocols. (CVE-2020-10136 CVE-2024-7595)

RapidResetClient

Examples for Implementing cve-2023-44487 ( HTTP/2 Rapid Reset Attack ) Concept

Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487)

Regular expression matching for URL's. Maintained, safe, and browser-friendly version of url-regex. Resolves CVE-2020-7661 for Node.js servers.

DDoS Tool which exploits vulnerability CVE-2004-2449 from vendor GameSpy (now known as OpenSpy). User is prompted for input IP address, and port.…

Zeek plugin detecting CallStranger (CVE-2020-12695) exploitation via UPnP SUBSCRIBE/NOTIFY analysis, identifying DDoS amplification, data…

PoC for distributed NTP reflection DoS (CVE-2013-5211)

Sockstress (CVE-2008-4609) DDoS implementation written in Go

Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software