
BrowserBox
💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.

💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

A tool to make socks connections through HTTP agents

DejaVU - Open Source Deception Framework

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

API Scraper Agent for Web API's

Test for CVE-2000-0649, and return an IP address if vulnerable

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes…


CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

Internal Hostname Disclosure Vulnerability

The detection of internal security controls at a company

Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC

Internal network scanner through Gluu IAM blind ssrf