
netlas-cookbook
The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

Searching for virtual hosts among non-resolvable domains

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

how to look for Leaked Credentials !

Tips on how to write exploit scripts (faster!)

A OSINT project that explores how to dump data from React

The vulnerable application that will teach you how to hack WebSockets

Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.

SAPGateBreaker is a PoC exploit for CVE-2022-22536, a critical HTTP Request Smuggling vulnerability in SAP NetWeaver. It demonstrates how to bypass…

Demonstrates a middleware bypass vulnerability (CVE-2025-29927) in Next.js, showing how to exploit the x-middleware-subrequest header to access…

Learnings on how to verify if vulnerable to Ghostcat (aka CVE-2020-1938)

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

The goal of this project is to demonstrate the log4j cve-2021-44228 exploit vulnerability in a spring-boot setup, and to show how to fix it.

Proof-of-concept exploit for CSRF to RCE in Backdrop CMS 1.20 (CVE-2021-45268) using malicious plugin upload.

Checks if your Chrome version is vulnerable to CVE-2025-5419, from the browser

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

[NEW] : Mega Bot ☣ Scanner & Auto Exploiter