
keyFinder
Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

Development has moved to https://codeberg.org/librewolf/source

An updated collection of resources targeting browser-exploitation.

A personalized/enhanced re-creation of the Darkhotel "Double Star" APT exploit chain with a focus on Windows 8.1 and mixed with some of my own…

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…

Neto | A tool to analyse browser extensions

A collection of web browser CTF challenges and solutions.

CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)

https://addons.mozilla.org/addon/redactkit/ A Firefox extension that redacts sensitive words (e.g., names, emails, phone no.) in real-time across…

Exploit for CVE-2019-9810 Firefox on Windows 64-bit.

PoC for CVE-2018-18500 - Firefox Use-After-Free

A tool to parse Firefox and Chrome HSTS databases into forensic artifacts!

Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served…

Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process…

Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original…

A tool that transforms Firefox browsers into a penetration testing suite