
TPASLog4ShellPoC
Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's…

Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's…

Spring messaging STOMP protocol RCE

spring-core单个图形化利用工具,CVE-2022-22965及修复方案已出

Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.

Vulnerable configuration Apache HTTP Server version 2.4.49

CVE-2020-3452 exploit

Exploit for CVE-2019-9810 Firefox on Windows 64-bit.

Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

Fuzz 401/403/404 pages for bypasses

Research on GraphQL from an AppSec point of view.

Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, and rule types

Http request smuggling vulnerability scanner

An automatic SQL Injection tool which takes advantage of ~DorkNet~ Googler, Ddgr, WhatWaf and sqlmap.

A more useful CSRF PoC generator on Burp Suite

Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.

A friend of SQLmap which will do what you always expected from SQLmap.

[POC] Asynchronous reverse shell using the HTTP protocol.