
CVE-2017-7921-Research-Toolkit
用于借助FOFA快速测试海康威视的CVE-2017-7921漏洞,并且给出登陆账号和密码,并输出json文件。

用于借助FOFA快速测试海康威视的CVE-2017-7921漏洞,并且给出登陆账号和密码,并输出json文件。

Suka suka lah

Nounours is a tool designed to test APP_KEYs at scale on Laravel applications.

Python toolkit for authorized testing of CVE-2021-43798 Grafana path traversal, with arbitrary file read PoC, secret decryption, and user hash export…

A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications.

HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras…

Burp Suite/antsword - Interactive shell (HTTP hijack + POST + AES-256-CBC/BASE64)

A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt…

Decrypts Hikvision IP camera configuration files extracted via CVE-2017-7921 authentication bypass, recovering user credentials from weakly encrypted…

Laravel Crypto Killer Mass Scanner (CVE-2024-55555)

PoC of CVE-2025-24659

Exploit for CVE-2024-43044 enabling arbitrary file read from Jenkins controller to extract and decrypt credentials.xml using secret keys.

This Tool To Test Machine Keys In View State

Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

Resources and PoCs

Proof-of-concept demonstrating command injection via crafted arguments in Windows BAT file execution, exploiting CVE-2024-24576 to achieve arbitrary…

Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)

A portable, padding oracle exploit API