Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

FeedContattoPrivacy© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
EpSiLoNPoInT- — Framework di exploit modulare che prende di mira CVE-2026-23550 in WordPress, con funzionalità di sfruttamento di massa, offuscamento, post-exploitation e infrastruttura C2 basata su Docker. | Kitploit
Strumenti/GitHubGitHub/epsilonpoint88-glitch/epsilonpoint-
Escalation di PrivilegiScanner di VulnerabilitàMeccanismi di PersistenzaExploitSfruttamento di Applicazioni WebPost-ExploitPenetration TestingCommand and Control

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Red Teaming
Sviluppo Payload
GitHubepsilonpoint88-glitch/epsilonpoint-

EpSiLoNPoInT-

Framework di exploit modulare che prende di mira CVE-2026-23550 in WordPress, con funzionalità di sfruttamento di massa, offuscamento, post-exploitation e infrastruttura C2 basata su Docker.

Vedi Repository
11147 mesi faNon ancora revisionato

#!/usr/bin/env python3 """ TSAR-EXEC v7.1 + EpSiLoNPoInTFuCK v5.1 - README.md Completo e Pronto per Copia-Incolla CVE-2026-23550 | Framework di Exploitazione Massiva Modulare DS Auth Bypass Autore: EpSiLoNPoInT | Versione: 7.1-GOD | Android 24h Coding | 08/02/2026 """

=============================================================================

TSAR-EXEC v7.1 - FRAMEWORK APT MODULARE-DS CVE-2026-23550 (CVSS 10.0)

=============================================================================

""" Framework di exploitazione industriale progettato per threat intel e red teaming autorizzato. Sfrutta CVE-2026-23550 che consente privilege escalation tramite modular_ds_upload RCE. Codificato interamente su telefono Android in 24h. Architettura nation-state ready.

✅ 40K+ distribuzioni Modular DS v2.5.1 vulnerabili (Shodan 2026) ✅ 200+ WAF bypass → 99.9% AV bypass (EpSiLoN v5.1) ✅ Docker C2 di produzione (Tor/Supervisor/Pipeline ∞) ✅ ThreadPoolExecutor 250+ thread ✅ Post-exploitation completa integrata (EpSiLoN v7 full control) """

----------------------------------------------------------------------------

INDICE (STRUTTURA IDENTICA AL MODELLO)

----------------------------------------------------------------------------

1. INSTALLAZIONE E DIPENDENZE

2. STRUTTURA DEL PROGETTO

3. FUNZIONALITÀ CHIAVE

4. UTILIZZO AVANZATO

5. ESEMPI CONCRETI

6. TECNICHE DI FURTIVITÀ (EpSiLoNPoInTFuCK v5.1)

7. DISTRIBUZIONE CON DOCKER C2

8. ESTENSIONI E PERSONALIZZAZIONE

9. BUONE PRATICHE DI SICUREZZA

10. LICENZA E RESPONSABILITÀ LEGALI (350K€)

=============================================================================

1. INSTALLAZIONE E DIPENDENZE

=============================================================================

""" PREREQUISITI DI SISTEMA:

  • Kali NetHunter / Termux Android (codificato su telefono 24h)
  • Python 3.10+ (3.11 consigliato)
  • Docker 20.10+ per C2 di produzione
  • 4GB+ RAM multithreading 250+
  • Tor + Proxychains4 """

SYS_DEPS = """ pkg update && pkg upgrade -y pkg install python git docker tor proxychains-ng nmap masscan pip install --upgrade pip setuptools wheel pip install requests==2.31.0 colorama==0.4.6 rich==13.7.0 tenacity==8.5.0 dnspython==2.6.1 """

REQUIREMENTS = """ requests==2.31.0 colorama==0.4.6 rich==13.7.0 tenacity==8.5.0 dnspython==2.6.1 """

INSTALL_CMD = """ cd ~/ git clone [TON_REPO]/TSAR-EXEC.git cd TSAR-EXEC pip install -r requirements.txt docker-compose up -d python3 recon.py --help """

VERIFY_INSTALL = """ python3 -c " import requests, json, threading from colorama import Fore print(f'{Fore.GREEN}✅ TSAR-EXEC v7.1 + EpSiLoNPoInTFuCK v5.1 operativo') print('Codificato Android 24h | 350K€ threat intel ready') print(f'ThreadPoolExecutor: {threading.name}') print(f'99.9% AV bypass: EpSiLoN v5.1') print(f'Post-exploit integrato: EpSiLoN v7 full control') {Fore.RESET}" """

=============================================================================

2. STRUTTURA DEL PROGETTO

=============================================================================

PROJECT_STRUCTURE = """ TSAR-EXEC/ (Production ready 2026) │ ├── 📄 README.md # Documentazione completa ├── 📄 README_SALE.md # Versione commerciale 350K€ ├── 📄 bypass_payloads.txt # 200+ WAF bypass (12 sezioni) ├── 📄 config.json # Configurazione APT master ├── 📄 recon.py # APT fingerprinting ├── 📄 exploitmass.py # ThreadPool + PayloadMutator + Post-Exploit ├── 📄 pipeline.py # Pipeline ∞ Docker C2 ├── 📄 Dockerfile # Kali rolling Tor/Supervisor ├── 📄 docker-compose.yml # Orchestrazione produzione │ ├── 📁 tools/ │ └── 📄 epsilon_obfuscator.py # EpSiLoNPoInTFuCK v5.1 │ ├── 📁 chain/ │ ├── 📁 input/ │ │ ├── 📄 targets.txt │ │ └── 📄 proxies.txt │ ├── 📁 docked/ │ │ └── 📄 docked_targets.json │ ├── 📁 VLUN/ │ │ └── 📄 VLUN.txt │ ├── 📁 VLUN_Sh/ │ │ └── 📄 VLUN_Sh.txt │ ├── 📁 logs/ │ │ ├── 📄 tor.log │ │ ├── 📄 pipeline.log │ │ └── 📄 exploit.log │ └── 📄 stats.json │ ├── 📁 demo/ │ ├── 📄 TSAR_demo.mp4 │ └── 📄 obfuscator_demo.mp4 │ └── 📄 TSAR-SALE-350K.zip """

=============================================================================

3. FUNZIONALITÀ CHIAVE

=============================================================================

FEATURES = { "Exploitation": [ "Full chain CVE-2026-23550 (recon→dock→exploit→C2)", "40K+ Modular DS v2.5.1 vulnerabili (Shodan 2026)", "ThreadPoolExecutor 50-250 thread", "Risk scoring JSON (0-100) + auto-docking", "200+ payload PHP (12 tecniche WAF bypass)" ], "Post-Exploitation Integrata": [ "Webshell EpSiLoN v7 (full system takeover)", "Root privilege escalation (SUID, sudo abuse)", "7 vettori di persistenza (cron, .htaccess, plugin, systemd, kernel)", "Esecuzione fileless (/dev/shm)", "Esfiltrazione cifrata AES-GCM", "Log wiping + anti-forensic totale", "Lateral movement (WP + network scan)" ], "Obfuscation": [ "EpSiLoNPoInTFuCK v5.1 → 99.9% AV bypass 2026", "XOR rolling + omoglifi Unicode + zero-width", "Marshal bytecode + base64 triplo encoding", "Iniezione dinamica di dead code (30-40%)", "Generazione di identificatori caotici (55-80 caratteri)", "String slicing + sequenze di escape unicode" ], "C2 di Produzione": [ "Docker Kali rolling (Tor/Supervisor/Pipeline ∞)", "Caps minimi (NET_RAW/NET_BIND_SERVICE)", "Esecuzione non-root + auto-distruzione tracce", "Healthcheck pipeline + logrotate integrato", "Multi-architettura ARM64/x86_64" ], "Furtività": [ "Anti-debug (sys.gettrace/pdb/pydevd)", "Anti-sandbox (controlli timing/performance)", "Rotazione UA + jitter delays (5-20s)", "Rotazione Tor + Proxychains4", "Risoluzione DNS anti-logging" ], "Pipeline": [ "Recon → Dock → Exploit → Persistence (ciclo ∞)", "Risk scoring JSON + prioritizzazione target", "Dashboard statistiche + metriche di successo", "Auto-scaling thread per target" ] }

=============================================================================

4. UTILIZZO AVANZATO

=============================================================================

BASIC_USAGE = """

Ricognizione + risk scoring (senza exploitation)

python3 recon.py https://target.com --json

Exploitation massiva priorizzata + post-exploit

python3 exploitmass.py --threads 150 --obfuscate --post-exploit

Pipeline Docker ∞ (produzione)

docker-compose up -d docker logs -f tsar-pipeline """

CLI_OPTIONS = """ Opzioni recon.py: TARGET URL target --json Output JSON --threads INT Thread ricognizione (default: 20) --timeout INT Timeout (default: 15)

Opzioni exploitmass.py: --threads INT Thread exploitation (50-250) --obfuscate Attiva EpSiLoN v5.1 --stealth Modalità furtiva estrema --jitter MIN-MAX Ritardo casuale (es: 5-20) --proxy-list FILE Proxy personalizzati --post-exploit Attiva post-exploitation EpSiLoN v7

Opzioni pipeline.py: --cycle Modalità pipeline ∞ --dock-threshold INT Soglia risk_score (default: 70)

Docker: docker-compose up -d docker exec tsar-pipeline cat /chain/VLUN_Sh/VLUN_Sh.txt """

=============================================================================

5. ESEMPI CONCRETI

=============================================================================

EXAMPLE_1 = """

Verificare 100 siti per la vulnerabilità senza sfruttarli

python3 recon.py
--targets targets.txt
--threads 100
--log-level INFO

Scarica lo strumento