Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

Exploit

Exploit refers to a piece of code or technique that takes advantage of a security vulnerability in a system, application, or network to cause unintended behavior. Exploits can be used by attackers to gain unauthorized access, escalate privileges, execute arbitrary code, or cause a denial of service. This topic covers the various types of exploits, such as zero-day exploits, remote code execution, and privilege escalation. It also explores the lifecycle of an exploit, from discovery and development to deployment and mitigation, and highlights the importance of vulnerability management and patching in preventing exploits.

https://github.com/nullarray/shellware

Persistent bind shell via pythonic shellcode execution, and registry tampering.

exploit pentest pentesting-windows persistence shellcode

Last synced: 14 Oct 2024

https://github.com/k8gege/jbossexploit

MSF moudle jboss invoke deploy getshell Exploit & Jboss jmx-console getshell exploit

exp exploit getshell jboss metasploit msf poc rce

Last synced: 13 Nov 2024

https://github.com/kotvnaskehitman4/nebula-executor

Nebula is a new Lua executor for Roblox. It's simple, straightforward, we ensure quick patches after Roblox updates.

bloxfruits-script cheat discord exploit exploiting lua roblox roblox-lua roblox-script roblox-scripts roblox-studio robloxdev rojo script

Last synced: 06 Dec 2024

https://github.com/rek7/zimbra-rce

Zimbra RCE PoC - CVE-2019-9670 XXE/SSRF

exploit python rce zimbra

Last synced: 29 Nov 2024

https://github.com/b4zinga/explib

Explib: Collections of poc and exp.

exploit poc python tools

Last synced: 18 Nov 2024

https://github.com/hugsy/hevd

Public repository for HEVD exploits

exploit hacksys hevd kernel pwn windbg windows

Last synced: 12 Oct 2024

https://github.com/notselwyn/exploits

Custom exploits

exploit linux proof-of-concept

Last synced: 27 Dec 2024

https://github.com/iricartb/advanced-sql-injection-scanner

Ivan Ricart Borges - Test for didactic purposes of web pages vulnerables to SQL injection using dbo database user with xp_cmdshell execution permissions. Using patterns from Internet search engines to extract potentially vulnerable web addresses and test them by changing the GET parameters using invalid Transact-SQL conversion function to cause through unhandled errors by IIS web server to show critical information. If certain features are given and using advanced injection techniques a malicious attacker could gain control of the entire system by executing shell commands in the SQL database engine.

c-sharp database dbo exploit iis injection microsoft rce scanner search-engine sqlserver transact-sql visual-studio vulnerability webserver xp-cmdshell

Last synced: 14 Nov 2024

https://github.com/kia87v73/roblox-bunni-executor

Bunni is a premier Roblox exploiting platform, renowned for its cutting-edge tools, rapid updates, and robust support. Developed by experienced professionals, it ensures maximum efficiency, security, and a seamless user experience with features like HWID spoofer and extensive script support.

cheats code developer exploit gaming github hacking injector lua modding open-source programming project

Last synced: 30 Dec 2024

https://github.com/nikewaybuck/nebula-executor

Nebula is a new Lua executor for Roblox. It's simple, straightforward, we ensure quick patches after Roblox updates.

bloxfruits-script cheat discord exploit exploiting lua roblox roblox-lua roblox-script roblox-scripts roblox-studio robloxdev rojo script

Last synced: 21 Dec 2024

https://github.com/sgabe/cve-2019-1253

AppXSvc Arbitrary File Security Descriptor Overwrite EoP

elevation-of-privilege eop exploit proof-of-concept vulnerability windows10

Last synced: 14 Dec 2024

https://github.com/cokebeer/go-cves

收录go语言编写的项目、框架和组件出现的cve,或者一些相关的利用方式的文章

bugbounty cve exploit go poc security

Last synced: 02 Dec 2024

https://github.com/deepsyx/vote-buster

Capcha+Email confirmation bypass script

bot bypass captcha cookie exploit recognization smtp-server tesseract

Last synced: 16 Nov 2024

https://github.com/tatapinhighcone74/roblox-synapse

Roblox Synapse Executor is a top-tier script execution tool for Roblox, valued for its advanced features and stability, enabling seamless Lua scripting for game modifications and customization.

authentication bloxfruit-script bloxfruits-autofarm-script executer exploit game gui hack lua nexus-roblox roblox roblox-lua roblox-script roblox-scriptbloxfruits-autofarm-script roblox-scripts roblox-synapse robloxscripts script-hub supported whitelist

Last synced: 09 Jan 2025

https://github.com/joseph21v/roblox-incognito

Incognito is a Roblox script executor known for its user-friendly interface and support for executing Lua scripts, providing enhanced gameplay and automation features. Regular updates ensure compatibility with Roblox's latest changes, though using it risks violating Roblox's terms of service.

exploit incognito incognito-crash incognito-discord incognito-download incognito-external incognito-fix incognito-key incognito-no-key incognito-update incognito-v2-download inkognito roblox roblox-incognito

Last synced: 03 Jan 2025

https://github.com/oppsec/pwnfaces

😛 Primefaces 5.X EL Injection Exploit (CVE-2017-1000486)

cve cve-2017-1000486 elinjection exploit golang linux primefaces redteam

Last synced: 08 Nov 2024

https://github.com/johnoseni1/router-hacker-exploit-and-extract-user-and-password-

This is a python wifi (router) hacker , having ability to search for mikrotic devices around you and get their <MAC> address then extract their user and password

exploit hacking ipaddress macaddress mikrotik port python safety

Last synced: 12 Oct 2024

https://github.com/camiloczz/scriptware

Scriptware Executor is a premium Roblox tool for Windows and macOS, renowned for its ability to execute Lua scripts efficiently, offering robust features for advanced game modifications and seamless gameplay enhancements.

backup borgbackup delayless exploit fe fluxus hack http krnl lua netbypass netless reanimate rest-api roblox rust script scriptware synapse tauri

Last synced: 14 Oct 2024

https://github.com/seclab-ucr/syzbridge

SyzBridge is a research project that adapts Linux upstream PoCs to downstream distributions. It provides rich interfaces that allow you to do a lot of cool things with Syzbot bugs

bug-triage exploit linux linux-kernel

Last synced: 22 Nov 2024

https://github.com/warflop/iot-mqtt-exploit

An tool for search IOT MQTT vulnerable with shodan

exploit iot mqtt shodan

Last synced: 15 Dec 2024

https://github.com/givenam/codex-roblox

Roblox Codex Executor supports low-end PCs and let you enjoy the stable and smooth. Codex stands out as the premier Roblox script executor, providing unparalleled functionality to effortlessly run scripts for your preferred Roblox games.

codex codex-roblox executer exploit game gui hack lua roblox script-hub supported trigon-download trigon-evo trigon-evo-download trigon-key trigon-script

Last synced: 12 Oct 2024

https://github.com/yallxe/hogg

Common vulnerability scanning on steroids ☄️

dns exploit network proxy rust rust-lang scanner secrets security sniffer vulnerabilities webscanner

Last synced: 26 Nov 2024

https://github.com/LukeBob-zz/C2-Pwn

Uses Shodan API to pull down C2 servers to run known exploits on them.

c2 exploit python rat shodan-api

Last synced: 17 Nov 2024

https://github.com/m3ssap0/spring-break_cve-2017-8046

This is a Java program that exploits Spring Break vulnerability (CVE-2017-8046).

cve-2017-8046 exploit security security-tools spring-break spring-data-rest vulnerability vulnerability-scanners

Last synced: 13 Nov 2024

https://github.com/egebalci/msf-self-defence

Self defense post module for metasploit

anti-detection defense exploit

Last synced: 18 Nov 2024

https://github.com/aydinnyunus/cve-2024-24576-exploit

CVE-2024-24576 Proof of Concept

1-day exploit rust security

Last synced: 11 Nov 2024

https://github.com/owlinux1000/arm_exploit

ARM Exploit 開発のためのトレーニングリポジトリ

arm exploit

Last synced: 15 Nov 2024

https://github.com/Warflop/IOT-MQTT-Exploit

An tool for search IOT MQTT vulnerable with shodan

exploit iot mqtt shodan

Last synced: 17 Nov 2024

https://github.com/p0dalirius/binaryexploitation

A massive documentation about binary protections, exploitation techniques, and computer architecture concepts.

binary buffer exploit exploitation overflow pwn system

Last synced: 17 Dec 2024

https://github.com/ait-testbed/attackmate

AttackMate is an attack orchestration tool that executes full attack-chains based on playbooks.

api attack automation automation-framework cybersecurity exploit metasploit orchestration pentest python redteam rootkit security sliver testbed training

Last synced: 09 Nov 2024

https://github.com/software-engineering-and-security/inspector-gadget

Inspector-gadget (a.k.a. PSHAPE - Practical Support for Half-Automated Program Exploitation) is an open source tool which assists analysts in exploit development. It discovers gadgets, chains gadgets together, and ensures that side effects such as register dereferences do not crash the program.

exploit gadget-chain gadgets inspector-gadget pshape register vulnerability

Last synced: 08 Nov 2024

https://github.com/davidbuchanan314/wifi-sdcf

Reverse Engineering notes on the Dxingtek/Keytech(?) WiFi@SDCF card

exploit iot reverse-engineering

Last synced: 07 Nov 2024

https://github.com/tiotails22/roblox-synapse

Roblox Synapse Executor is a top-tier script execution tool for Roblox, valued for its advanced features and stability, enabling seamless Lua scripting for game modifications and customization.

bloxfruit-script exploit lua roblox roblox-electron roblox-electron-free roblox-electron-script roblox-electron-scripts roblox-electron-v3 roblox-execute roblox-executer roblox-executer-solara roblox-script roblox-scripts roblox-solara roblox-solara-free roblox-solara-key roblox-synapse roblox-synapsex roblox-synapsex-free

Last synced: 12 Oct 2024

https://github.com/mido21102/xeno-executor

Xeno-Executor is a powerful open-source automation tool designed to simplify and streamline the execution of tasks and processes.

csharp delta-exploits exploit ldplayer lua luau roblox roblox-lua roblox-menu roblox-script roblox-scripts roblox-xeno xeno-executor xeno-roblox

Last synced: 23 Jan 2025

https://github.com/CnHack3r/Penetration_PoC

FROM:@Mr-xn 渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss penetration-testing-poc csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

bypass cms-exploits cms-framework cobaltstrike cve exploit rce sql-scanner

Last synced: 23 Oct 2024

https://github.com/chocapikk/cve-2023-4966

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

citrix cve-2023-4966 exploit exploitation infosec memory-leak netscaler network-security open-source pentesting python security security-research session-tokens vulnerability

Last synced: 12 Dec 2024

https://github.com/gousaiyang/pickleassem

A simple pickle assembler to make handcrafting pickle bytecode easier.

assembler bytecode ctf exploit pickle security security-tools

Last synced: 14 Oct 2024

https://github.com/byt3n33dl3/camhoundad

Automated Exploit scanners for public Camera, CCTV's, and Capture Devices.

camera cctv exploit surveillance trust-attack

Last synced: 19 Dec 2024

https://github.com/0x00-0x00/cve-2016-2098

Ruby On Rails unrestricted render() exploit

exploit rail rails render ruby

Last synced: 22 Nov 2024

https://github.com/emo-crab/scap-rs

National Vulnerability Database (NVD) implemented by rust

actix-web cpe cve cvss cvssv3 cvssv4 cwe exploit nuclei-templates nvd rust scap yew

Last synced: 18 Nov 2024

https://github.com/thewhiteh4t/cve-2020-9375

TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.

cve cve-2020-9375 exploit tp-link tplink

Last synced: 15 Nov 2024

https://github.com/qkaiser/voodoo

This repository holds proof-of-concepts for the VOOdoo vulnerabilities found in NETGEAR CG3100 and CG3700B cable modems provided by VOO to its subscribers.

cg3100 cg3700 exploit netgear voo wireless

Last synced: 16 Dec 2024

https://github.com/0x00-0x00/-cve-2017-9805

Exploit script for Apache Struts2 REST Plugin XStream RCE (‎CVE-2017-9805)

apache cve exploit struts

Last synced: 22 Nov 2024

https://github.com/uni-due-syssec/teerex-exploits

PoC exploits against various SGX enclaves

exploit memory-corruption poc sgx

Last synced: 09 Nov 2024

https://github.com/krishpranav/exploit-framework

A multiple reverse shell sessions/clients manager via terminal written in go

ctf exploit exploit-framework exploitation go golang reverse-shell reverse-shell-as-a-service

Last synced: 15 Oct 2024

https://github.com/jaydenth/roblox-synapse

Roblox Synapse Executor is a top-tier script execution tool for Roblox, valued for its advanced features and stability, enabling seamless Lua scripting for game modifications and customization.

authentication bloxfruit-script bloxfruits-autofarm-script executer exploit game gui hack lua nexus-roblox roblox roblox-lua roblox-script roblox-scriptbloxfruits-autofarm-script roblox-scripts roblox-synapse robloxscripts script-hub supported whitelist

Last synced: 30 Oct 2024

https://github.com/paulveillard/cybersecurity-exploit-development

An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Exploit Development.

code-execution developer developer-experience developer-tools development development-tools exploit exploitation exploitation-framework exploitation-frameworks exploitation-menu vulnerability-detection

Last synced: 07 Dec 2024

https://github.com/noraj/bludit-auth-bf-bypass

Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass

authentication bludit bruteforce bypass cms cve-2019-17240 exploit poc proof-of-concept

Last synced: 07 Nov 2024

https://github.com/hktalent/weblogic_java_des

weblogic T3 collections java InvokerTransformer Transformer InvokerTransformer weblogic.jndi.WLInitialContextFactory

collections deserialization exploit hacker hacking-tool invokertransformer java rce remote-control remote-execution tools transformer weblogic

Last synced: 19 Nov 2024

https://github.com/i32-sudo/vulnerablepatchguardexploit

A Vulnerable PatchGuard Exploit that can be used to disable PatchGuard on Runtime.

battleye be bypass exploit latest patchguard pg undetected working

Last synced: 15 Jan 2025

https://github.com/cxm95/ida_wrapper

An IDA_Wrapper for linux, shipped with an Function Identifier. It works well with Driller on static linked binaries.

aeg angr driller exploit flair ida static-analysis

Last synced: 16 Nov 2024

https://github.com/xsscx/cve-2017-5638

Example PoC Code for CVE-2017-5638 | Apache Struts Exploit

apache code content-type cve-2017-5638 exploit poc python struts2

Last synced: 11 Nov 2024

https://github.com/0xinfection/epscalate

Exploit for elevation of privilege vulnerability in QuickHeal's Seqrite EPS (CVE-2023-31497).

cve-2023-31497 endpoint-security exploit privilege-escalation

Last synced: 07 Nov 2024

https://github.com/m8sec/eaprimer

C# project to Reflectively load .Net assemblies in memory

amsi csharp executing-assemblies exploit net-assemblies pentesting powershell windows

Last synced: 30 Oct 2024

https://github.com/noraj/Bludit-auth-BF-bypass

Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass

authentication bludit bruteforce bypass cms cve-2019-17240 exploit poc proof-of-concept

Last synced: 21 Nov 2024

https://github.com/qeeqbox/falcon

Collection of exploits that were verified by an automated system

cve exploit patch python

Last synced: 15 Nov 2024

https://github.com/b4keSn4ke/Invoke-WinSATBypass

Powershell UAC Bypass script leveraging WinSAT.exe

exploit exploitation exploits powershell uac uac-bypass uacbypass windows windows-10

Last synced: 04 Dec 2024

https://github.com/voidsec/cve-2020-1337

CVE-2020-1337 a bypass of (PrintDemon) CVE-2020-1048’s patch

0day cve-2020-1048 cve-2020-1337 exploit faxhell poc printdemon voidsec windows

Last synced: 24 Nov 2024

https://github.com/p0dalirius/cve-2018-16763-fuelcms-1.4.1-rce

Exploit to trigger RCE for CVE-2018-16763 on FuelCMS <= 1.4.1 and interactive shell.

cms cve-2018-16763 exploit fuelcms

Last synced: 30 Dec 2024

https://github.com/shelld3v/python-shell-cheat-sheet

Full python reverse shell and bind shell payloads

bind-shell cheat-sheet exploit hacking python python3 reverse-shell security shell

Last synced: 27 Dec 2024

https://github.com/mlgmxyysd/f21proinjector

Exploit the vulnerability to install arbitrary applications in k61v1 without ROOT

android exploit exploitation hacking hacktoberfest php

Last synced: 17 Nov 2024

https://github.com/demining/twist-attack

In this article, we will implement a Twist Attack with an example and show how, using certain points on the secp256k1 elliptic curve, we can get partial private key values ​​and restore a Bitcoin Wallet within 5-15 minutes using “Sagemath pollard rho function: (discrete_log_rho)” and “ Chinese Remainder Theorem” .

attack attacker bitcoin bitcoin-wallet blockchain blockchain-technology cryptocurrency exploit exploiting exploiting-vulnerabilities hack hacking vulnerabilities vulnerability vulnerability-scanners

Last synced: 11 Jan 2025

https://github.com/voidsec/cve-2019-5624

A proof of concept for Metasploit's CVE-2019-5624 vulnerability (Rubyzip insecure ZIP handling RCE)

cve-2019-5624 exploit metasploit metasploit-framework poc rce rubyzip

Last synced: 24 Jan 2025

https://github.com/mustafadalga/multi-client-reverse-shell

A multi-client reverse shell that allows multiple connections from target computers || Hedef bilgisayarlardan gelen birden fazla bağlantıya izin veren çoklu istemcili reverse shell.

exploit hack hacking hacking-attack-tools hacking-code hacking-tool hacking-tools multi-reverse-shell python-for-hacking python-for-security python-reverse-shell python3 reverse-shell shell shell-script shell-scripts shellcode shellscript

Last synced: 16 Oct 2024

https://github.com/josephgreens/roblox-synapse

Roblox Synapse Executor is a top-tier script execution tool for Roblox, valued for its advanced features and stability, enabling seamless Lua scripting for game modifications and customization.

authentication bloxfruit-script bloxfruits-autofarm-script executer exploit game gui hack lua nexus-roblox roblox roblox-lua roblox-script roblox-scriptbloxfruits-autofarm-script roblox-scripts roblox-synapse robloxscripts script-hub supported whitelist

Last synced: 06 Dec 2024

https://github.com/depau/fastgate-python

Python tools for Fastweb FastGATE exploits

exploit pwn python router

Last synced: 15 Nov 2024

https://github.com/Supersonic/Wallbreak

Exploit app for CVE-2021-39670 and CVE-2021-39690, two permanent denial-of-service vulnerabilities in Android's wallpaper system

android cve exploit security vrp

Last synced: 23 Oct 2024

https://github.com/jus7vb76w/roblox-vega

VegaX is a powerful Windows PC executor for Roblox, designed to run Lua scripts efficiently, enabling users to unlock advanced game modifications and enhance their overall gameplay experience.

exploit incognito incognito-crash incognito-discord incognito-download incognito-external incognito-fix incognito-key incognito-no-key roblox roblox-vega roblox-vega-key roblox-vega-update vega vega-crash vega-discord vega-download vega-external vega-no-key vega-v2-download

Last synced: 13 Dec 2024

https://github.com/p0dalirius/cve-2022-26159-ametys-autocompletion-xml

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.

ametys autocompletion cms exploit plugin

Last synced: 30 Dec 2024

https://github.com/gnebbia/shellcoder

Create shellcode from executable or assembly code

exploit exploitation perl shellcode

Last synced: 13 Nov 2024

https://github.com/xsscx/ios-arm-research

UPDATED: All the action is at https://github.com/xsscx/srd

development discovery exploit fuzzing vulnerability

Last synced: 11 Nov 2024

https://github.com/noraj/atmail-exploit-toolchain

AtMail Email Server Appliance 6.4 - Exploit toolchain (XSS > CSRF > RCE)

atmail csrf exploit plugin rce reverse-shell xss

Last synced: 07 Nov 2024

https://github.com/mustafadalga/code-injector

Aynı ağ içerisinde , ARP Spoofing saldırısı yapılmış hedef bilgisayarın ziyaret ettiği , HTTP protokolünü kullanan web sitelerine kod enjekte ederek manipüle etmenize yarayan bir script.

code-injection cyber-security cyber-threat-intelligence cybersecurity exploit hacker hacking hacking-code hacking-tool hacking-tools hackingtools python python-3 python-script python3 web-hackathon web-hacking website-hacking

Last synced: 17 Nov 2024

https://github.com/byt3n33dl3/thc-cartel

Configurations and Deprecated payloads. Some useful scripts for Cobaltstrike.

exploit kali-linux metasploit operating-system payloads pentesting shellcode

Last synced: 31 Oct 2024

https://github.com/AmoloHT/CVE-2022-26134

「💥」CVE-2022-26134 - Confluence Pre-Auth RCE

confluence cve cve-2022-26134 exploit hacking infosec rce security

Last synced: 23 Oct 2024

https://github.com/voidsec/solarputtydecrypt

A post-exploitation tool to decrypt SolarPutty's sessions files

decrypt exploit forensics postexploit postexplotation sessions solarputty

Last synced: 24 Nov 2024

https://github.com/0xbitx/dedsec_bkif

DEDSEC_BKIF is a keystroke injection tool for Android, Linux, and iOS.

bluetooth bluetooth-keystroke exploit keystroke keystroke-injection

Last synced: 14 Jan 2025

https://github.com/bcoles/serenity-exploits

Various exploits for SerenityOS

exploit serenityos

Last synced: 29 Oct 2024

https://github.com/theori-io/web3-publications

Collection of Web3 Audits and Publications by ChainLight of Theori

blockchain ethereum exploit fuzzing publications security smart-contract web3

Last synced: 14 Dec 2024

https://github.com/demining/twist-attack-2

In this article, we will implement a Twist Attack with an example and show how, using certain points on the secp256k1 elliptic curve, we can get partial private key values ​​and restore a Bitcoin Wallet within 5-15 minutes using “Sagemath pollard rho function: (discrete_log_rho)” and “ Chinese Remainder Theorem” .

attack attacker bitcoin bitcoin-wallet blockchain blockchain-technology cryptocurrency exploit exploiting exploiting-vulnerabilities hack hacking vulnerabilities vulnerability vulnerability-scanners

Last synced: 11 Jan 2025

https://github.com/m4drat/CVE-2013-2028-Exploit

CVE-2013-2028 python exploit

cve exploit nginx pwn

Last synced: 23 Oct 2024