
rebindMultiA
DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where…

Investigation of a PAN-OS CVE-2024-3400 command injection attempt, analyzing payload delivery, internal processing, and execution validation based on…

This repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an…

Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228

Tool to discover external and internal network attack surface

Internal penetration testing tool for Linux that can be used to enumerate OS information, domain information, shares, directories, and users through…

Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes


An ADCS honeypot to catch attackers in your internal network.

Reverse engineering of the engine powering the PriPara games on arcade.

Python script to check Palo Alto firewalls for CVE-2024-3400 exploit attempts

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It…

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…


There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions …

Python and Powershell internal penetration testing framework

Microsoft Edge Elevation of Privilege Vulnerability