Updated 2026-04-30 22:20:13 +02:00
A Go-based, single-page web interface for managing Fail2ban. Built by Swissmakers.
Updated 2026-04-19 20:26:15 +02:00
CVE-2026-1731 - Critical command injection vulnerability in BeyondTrust Remote Support and Privileged Remote Access due to unsafe Bash arithmetic evaluation in a WebSocket-reachable script
Updated 2026-03-26 16:48:49 +01:00
A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.
Updated 2026-03-26 16:44:55 +01:00
A Coverage Explorer for Reverse Engineers
Updated 2026-03-26 16:18:32 +01:00
Generate FUD backdoors
Updated 2026-03-26 10:12:08 +01:00
Aspyco is a python script that permits to upload a local binary through SMB on a remote host. Then it remotely connects to svcctl named pipe through DCERPC to create and start the binary as a service.
Updated 2026-03-26 09:46:06 +01:00
The Havoc Framework
Updated 2026-03-26 09:42:12 +01:00
PoC for a Havoc agent/handler setup with all C2 traffic routed through GitHub. No direct connections: all commands and responses are relayed through Issues and Comments for maximum stealth.
Updated 2026-03-26 09:38:02 +01:00
Updated 2026-03-26 09:31:49 +01:00
🛡️ Proof of Concept (PoC) for CVE-2025-32463 — Local privilege escalation in sudo (versions 1.9.14 to 1.9.17). This exploit abuses the --chroot option and a malicious nsswitch.conf to execute arbitrary code as root. ⚠️ For educational and authorized testing only.
Updated 2026-03-26 09:19:08 +01:00
Updated 2026-03-25 17:42:34 +01:00