
not-slithering-anywhere
The Python Version of our Not Go-ing Anywhere Vulnerable Application

The Python Version of our Not Go-ing Anywhere Vulnerable Application

Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.

Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis

Burp Suite extension enhancing Collaborator with context capture, polling history, and optional AES-encrypted authentication for private server…

Proof-of-concept reproduction of an nginx heap overflow and info leak (CVE-2026-42533) with two attack surfaces, debug analysis, and a full RCE chain.

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

SVG Analysis and generation tools for commonly seen SVG attachment phishing

adaptive agents for dynamic web penetration testing

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava


MeowEye is a real-time scanner for identifying multiple web vulnerabilities in live applications.

Web application security scanner created by lcamtuf for google - Unofficial Mirror

Log4j漏洞(CVE-2021-44228)的Burpsuite检测插件

Java library for XML serialization and deserialization, with a focus on the CVE-2020-26217 deserialization vulnerability exploit.

Burp Suite extension to detect the Next.js / React Server Components (RSC) Remote Code Execution vulnerability (CVE-2025-55182 & CVE-2025-66478).

Go tool and Nuclei template for testing James Kettle's (CVE-2025-32094) HTTP/1.1 must die: the desync endgame

This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…