Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
EpSiLoNPoInT- — Framework d'exploitation modulaire ciblant CVE-2026-23550 dans WordPress, avec exploitation de masse, obfuscation, post-exploitation et infrastructure C2 basée sur Docker. | Kitploit
Outils/GitHubGitHub/epsilonpoint88-glitch/epsilonpoint-
Escalade de PrivilègesScanners de VulnérabilitésMécanismes de PersistanceExploitationExploitation d'Applications WebPost-ExploitationTests d'IntrusionCommandement et Contrôle

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Red Teaming
Développement de Charges Utiles
GitHubepsilonpoint88-glitch/epsilonpoint-

EpSiLoNPoInT-

Framework d'exploitation modulaire ciblant CVE-2026-23550 dans WordPress, avec exploitation de masse, obfuscation, post-exploitation et infrastructure C2 basée sur Docker.

Voir le dépôt
1114il y a 7 moisPas encore vérifié

#!/usr/bin/env python3 """ TSAR-EXEC v7.1 + EpSiLoNPoInTFuCK v5.1 - README.md Complet et Prêt à Copier-Coller CVE-2026-23550 | Framework d'Exploitation Massive Modular DS Auth Bypass Auteur: EpSiLoNPoInT | Version: 7.1-GOD | Android 24h Coding | 08/02/2026 """

=============================================================================

TSAR-EXEC v7.1 - FRAMEWORK APT MODULAR-DS CVE-2026-23550 (CVSS 10.0)

=============================================================================

""" Framework d'exploitation industrielle conçu pour threat intel et red teaming autorisé. Exploite CVE-2026-23550 permettant privilege escalation via modular_ds_upload RCE. Codé entièrement sur téléphone Android en 24h. Architecture nation-state ready.

✅ 40K+ déploiements Modular DS v2.5.1 vulnérables (Shodan 2026) ✅ 200+ WAF bypass → 99.9% AV bypass (EpSiLoN v5.1) ✅ Docker C2 production (Tor/Supervisor/Pipeline ∞) ✅ ThreadPoolExecutor 250+ threads ✅ Post-exploitation complète embarquée (EpSiLoN v7 full control) """

----------------------------------------------------------------------------

TABLE DES MATIÈRES (STRUCTURE IDENTIQUE MODÈLE)

----------------------------------------------------------------------------

1. INSTALLATION ET DÉPENDANCES

2. STRUCTURE DU PROJET

3. FONCTIONNALITÉS CLÉS

4. UTILISATION AVANCÉE

5. EXEMPLES CONCRETS

6. TECHNIQUES DE FURTIVITÉ (EpSiLoNPoInTFuCK v5.1)

7. DÉPLOIEMENT AVEC DOCKER C2

8. EXTENSIONS ET PERSONNALISATION

9. BONNES PRATIQUES DE SÉCURITÉ

10. LICENCE ET RESPONSABILITÉS LÉGALES (350K€)

=============================================================================

1. INSTALLATION ET DÉPENDANCES

=============================================================================

""" PRÉREQUIS SYSTÈME:

  • Kali NetHunter / Termux Android (codé téléphone 24h)
  • Python 3.10+ (3.11 recommandé)
  • Docker 20.10+ pour C2 production
  • 4Go+ RAM multithreading 250+
  • Tor + Proxychains4 """

SYS_DEPS = """ pkg update && pkg upgrade -y pkg install python git docker tor proxychains-ng nmap masscan pip install --upgrade pip setuptools wheel pip install requests==2.31.0 colorama==0.4.6 rich==13.7.0 tenacity==8.5.0 dnspython==2.6.1 """

REQUIREMENTS = """ requests==2.31.0 colorama==0.4.6 rich==13.7.0 tenacity==8.5.0 dnspython==2.6.1 """

INSTALL_CMD = """ cd ~/ git clone [TON_REPO]/TSAR-EXEC.git cd TSAR-EXEC pip install -r requirements.txt docker-compose up -d python3 recon.py --help """

VERIFY_INSTALL = """ python3 -c " import requests, json, threading from colorama import Fore print(f'{Fore.GREEN}✅ TSAR-EXEC v7.1 + EpSiLoNPoInTFuCK v5.1 opérationnel') print('Codé Android 24h | 350K€ threat intel ready') print(f'ThreadPoolExecutor: {threading.name}') print(f'99.9% AV bypass: EpSiLoN v5.1') print(f'Post-exploit embarqué: EpSiLoN v7 full control') {Fore.RESET}" """

=============================================================================

2. STRUCTURE DU PROJET

=============================================================================

PROJECT_STRUCTURE = """ TSAR-EXEC/ (Production ready 2026) │ ├── 📄 README.md # Documentation complète ├── 📄 README_SALE.md # Version commerciale 350K€ ├── 📄 bypass_payloads.txt # 200+ WAF bypass (12 sections) ├── 📄 config.json # Configuration APT master ├── 📄 recon.py # APT fingerprinting ├── 📄 exploitmass.py # ThreadPool + PayloadMutator + Post-Exploit ├── 📄 pipeline.py # Pipeline ∞ Docker C2 ├── 📄 Dockerfile # Kali rolling Tor/Supervisor ├── 📄 docker-compose.yml # Orchestration production │ ├── 📁 tools/ │ └── 📄 epsilon_obfuscator.py # EpSiLoNPoInTFuCK v5.1 │ ├── 📁 chain/ │ ├── 📁 input/ │ │ ├── 📄 targets.txt │ │ └── 📄 proxies.txt │ ├── 📁 docked/ │ │ └── 📄 docked_targets.json │ ├── 📁 VLUN/ │ │ └── 📄 VLUN.txt │ ├── 📁 VLUN_Sh/ │ │ └── 📄 VLUN_Sh.txt │ ├── 📁 logs/ │ │ ├── 📄 tor.log │ │ ├── 📄 pipeline.log │ │ └── 📄 exploit.log │ └── 📄 stats.json │ ├── 📁 demo/ │ ├── 📄 TSAR_demo.mp4 │ └── 📄 obfuscator_demo.mp4 │ └── 📄 TSAR-SALE-350K.zip """

=============================================================================

3. FONCTIONNALITÉS CLÉS

=============================================================================

FEATURES = { "Exploitation": [ "Full chain CVE-2026-23550 (recon→dock→exploit→C2)", "40K+ Modular DS v2.5.1 vulnérables (Shodan 2026)", "ThreadPoolExecutor 50-250 threads", "Risk scoring JSON (0-100) + auto-docking", "200+ PHP payloads (12 techniques WAF bypass)" ], "Post-Exploitation Embarquée": [ "EpSiLoN v7 webshell (full system takeover)", "Root privilege escalation (SUID, sudo abuse)", "7 vecteurs persistence (cron, .htaccess, plugin, systemd, kernel)", "Fileless execution (/dev/shm)", "Exfiltration chiffrée AES-GCM", "Log wiping + anti-forensic total", "Lateral movement (WP + network scan)" ], "Obfuscation": [ "EpSiLoNPoInTFuCK v5.1 → 99.9% AV bypass 2026", "XOR rolling + homoglyphes Unicode + zero-width", "Marshal bytecode + base64 triple encoding", "Dead code injection dynamique (30-40%)", "Chaotic identifier generation (55-80 chars)", "String slicing + unicode escape sequences" ], "C2 Production": [ "Docker Kali rolling (Tor/Supervisor/Pipeline ∞)", "Caps minimal (NET_RAW/NET_BIND_SERVICE)", "Non-root execution + auto-destruction traces", "Healthcheck pipeline + logrotate intégré", "Multi-architecture ARM64/x86_64" ], "Furtivité": [ "Anti-debug (sys.gettrace/pdb/pydevd)", "Anti-sandbox (timing/performance checks)", "UA rotation + jitter delays (5-20s)", "Tor + Proxychains4 rotation", "DNS resolution anti-logging" ], "Pipeline": [ "Recon → Dock → Exploit → Persistence (∞ cycle)", "JSON risk scoring + target prioritization", "Stats dashboard + success metrics", "Auto-scaling threads par cible" ] }

=============================================================================

4. UTILISATION AVANCÉE

=============================================================================

BASIC_USAGE = """

Reconnaissance + risk scoring (sans exploitation)

python3 recon.py https://target.com --json

Exploitation massive priorisée + post-exploit

python3 exploitmass.py --threads 150 --obfuscate --post-exploit

Pipeline Docker ∞ (production)

docker-compose up -d docker logs -f tsar-pipeline """

CLI_OPTIONS = """ Options recon.py: TARGET URL cible --json JSON output --threads INT Threads recon (default: 20) --timeout INT Timeout (default: 15)

Options exploitmass.py: --threads INT Threads exploitation (50-250) --obfuscate Activer EpSiLoN v5.1 --stealth Mode furtif extrême --jitter MIN-MAX Délai aléatoire (ex: 5-20) --proxy-list FILE Proxies personnalisés --post-exploit Activer post-exploitation EpSiLoN v7

Options pipeline.py: --cycle Mode pipeline ∞ --dock-threshold INT Seuil risk_score (default: 70)

Docker: docker-compose up -d docker exec tsar-pipeline cat /chain/VLUN_Sh/VLUN_Sh.txt """

=============================================================================

5. EXEMPLES CONCRETS

=============================================================================

EXAMPLE_1 = """

Vérifier 100 sites pour la vulnérabilité sans les exploiter

python3 recon.py
--targets targets.txt
--threads 100
--log-level INFO

Résultat:

- Fichier chain/docked_targets.json avec les cibles priorisées

- Logs détaillés dans chain/logs/exploit.log

"""

Télécharger l’outil