
rebindMultiA
DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

Automated man-in-the-middle attack tool.

This is a project about attacking and gathering information of the windows machines which is connected in the same network by using java programs

INSTA_CYBER is a Python-powered ethical hacking tool designed for educational and research purposes. Built by Muhammad Sabir Ali (INNO_CYBER), this…

Maps attack surface of GWT applications by extracting obfuscated RPC endpoints and generating serialized request payloads for security testing.

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

WordPress pentest tool

Academic purposes only. Attack against Salesforce lightning with guest privilege.

A comprehensive Python testing tool for CVE-2023-44487, the HTTP/2 Rapid Reset vulnerability. This enhanced version provides granular control over…

Passive recon & attack surface mapper — zero requests sent

Exploit tool for Apache 2.4.49-2.4.50 path traversal and RCE (CVE-2021-41773, CVE-2021-42013). Scans URL lists, works with CGI and non-CGI, and…

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

Automated exploit tool for CVE-2026-23869, a remote DoS in React Server Components. Includes PoC, Nuclei template, and scanning scripts for detection…

Exploit tool for CVE-2026-45833 in ChromaDB, enabling malicious model generation, reconnaissance, and data exfiltration from target collections via…

Security write-up for an IDOR in Concrete CMS exposing conversation ratings through missing authorization on the get_rating endpoint, with root…

Automated exploit tool for CVE-2023-32315 authentication bypass vulnerability. Scans single or bulk targets with multiprocessing and automatic login…

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.