Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

Exploit

Exploit refers to a piece of code or technique that takes advantage of a security vulnerability in a system, application, or network to cause unintended behavior. Exploits can be used by attackers to gain unauthorized access, escalate privileges, execute arbitrary code, or cause a denial of service. This topic covers the various types of exploits, such as zero-day exploits, remote code execution, and privilege escalation. It also explores the lifecycle of an exploit, from discovery and development to deployment and mitigation, and highlights the importance of vulnerability management and patching in preventing exploits.

https://github.com/0x00-0x00/cve-2015-3224

Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224

console cve exploit rails ruby

Last synced: 22 Jan 2025

https://github.com/lbirchler/sys-call

Linux syscall implementations, calling conventions, and shellcode examples

assembly cli exploit linux shellcode syscalls

Last synced: 01 Feb 2025

https://github.com/a0zhar/ps4payloadloader

This repository will be maintained by me. Super simple to use! It has everything needed to build Your own MiraLoader or Payload Launcher refrenced in the PS4JB Repo by Sleirsgoevy

c exploit freebsd playstation4 ps4 ps4-jailbreak ps4-payload ps4exploit ps4jb ps4payload

Last synced: 20 Jan 2025

https://github.com/p1ckzi/cve-2022-35513

CVE-2022-35513 | blink1-pass-decrypt

blink1-pass-decrypt blink1control2 cve cve-2022-35513 exploit

Last synced: 30 Jan 2025

https://github.com/hunthubspace/cve-2024-0757-exploit

A PoC Exploit for CVE-2024-0757 - Insert or Embed Articulate Content into WordPress Remote Code Execution (RCE)

bugbounty cve ethical-hacking exploit penetration-testing web

Last synced: 31 Jan 2025

https://github.com/monke443/cve-2023-40028-ghost-arbitrary-file-read

Arbitrary file read in Ghost-CMS allows an attacker to upload a malicious ZIP file with a symlink.

cve cve-2023-40028 exploit ghost-cms github pentesting security vulnerability

Last synced: 27 Dec 2024

https://github.com/drdataye/drxploit

DrXploit is a powerful and open-source penetration testing and exploitation tool for web applications. This tool is designed to automate the process of discovering and exploiting vulnerabilities, saving time and effort for security researchers.

bugbounty exploit exploit-db hacking hacking-tool hackweb python3 scanning

Last synced: 20 Nov 2024

https://github.com/x86-512/vxpp

A VFGadget finder script to facilitate Counterfeit Object-Oriented Programming (COOP) and Loop-Oriented Programming (LOP) attacks to bypass advanced security protections like CET and CFG.

binary-exploitation buffer-overflow code-reuse control-flow-guard control-flow-integrity coop exploit exploit-development intel-cet lop rop rop-gadgets ropgadget security-bypass uaf use-after-free

Last synced: 11 Nov 2024

https://github.com/renatoalencar/dlink-dir610-exploits

Exploits for CVE-2020-9376 and CVE-2020-9377

authentication-bypass dlink exploit remote-code-execution

Last synced: 07 Nov 2024

https://github.com/tigerclips1/ps4jb_update_downloader_usb

What this script does is auto download ps4JB updates that you choose to your USB automation for linux only

automation exploit firmware guide linux ps4 ps4-jailbreak python python-script python3 tigerclips1

Last synced: 07 Jan 2025

https://github.com/kernelerr/vlc-cve-2008-4654-exploit

An EXP could run on Windows x64 against CVE-2008-4654.

cve exploit out-of-memory vlc vlc-media-player

Last synced: 19 Jan 2025

https://github.com/randomrobbiebf/cve-2023-0630

CVE-2023-0630 - Slimstat Analytics < 4.9.3.3 - Subscriber+ SQL Injection

cve-2023-0630 exploit wordpress wordpress-plugin

Last synced: 21 Jan 2025

https://github.com/randomrobbiebf/cve-2024-0679

ColorMag <= 3.1.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

cve-2024-0679 exploit wordpress

Last synced: 21 Jan 2025

https://github.com/masasron/chameleondump

Dump RFID tag IDs from ChameleonUltra devices

ble chameleonultra exploit

Last synced: 22 Nov 2024

https://github.com/m3hu1/speedtyperexploit

speedtyper.dev exploit written in python

exploit

Last synced: 15 Jan 2025

https://github.com/kaanaryoverflow/ipfire-2-25-auth-rce

ipfire 2.25 authenticated remote code execution

exploit ipfire rce

Last synced: 05 Feb 2025

https://github.com/codeb0ss/cve-2024-1698-poc

Mass Exploit CVE-2024-1698 - Wordpress NotificationX <= 2.8.2 - SQL Injection

codeb0ss codeboss cve-2024 cve-2024-1698 cve-2024-1698-exp cve-2024-1698-poc exploit wordpress

Last synced: 13 Nov 2024

https://github.com/trigii/cve-2023-42860

Exploit for CVE-2023-42860

apple exploit fda macos root sip tcc

Last synced: 30 Jan 2025

https://github.com/n3rada/zero-effort

Exploiting CVE-2020-1472 vulnerability (a.k.a Zerologon) without effort.

active-directory cve-2020-1472 evil-winrm exploit impacket-secretsdump windows zerologon

Last synced: 28 Dec 2024

https://github.com/dubniczky/kernel-exploits

Kernel exploits consisting mostly of privilege escalation attacks against core components of Linux distribtions

cve exploit linux linux-exploits linux-kernel

Last synced: 06 Feb 2025

https://github.com/p1ckzi/nanocmshell

authenticated remote code execution via shell upload.

exploit file-upload nanocms nanocmshell php php-reverse-shell rce

Last synced: 06 Feb 2025

https://github.com/jenderal92/git-dump

This script is a tool to recursively download the contents of the '.git' directory from a website. Using Python and libraries like 'requests' and 'BeautifulSoup', this script examines the directory structure, downloads files, and identifies SHA-1 hashes within Git files.

exploit git git-download git-dumper git-dumper-python git-exposed git-vulnerability python python-git-dumper vulnerability vulnerability-git

Last synced: 13 Feb 2025

https://github.com/lololosys/exploitation_notes

This repository contain common exploitation primites for various platforms

exploit security-research

Last synced: 02 Feb 2025

https://github.com/ytisf/snmplicity

the Swiss Army Knife of the SNMP world, but, it's coded in Python, not made of stainless steel!

cisco code-execution exploit redteam-tools redteaming snmp

Last synced: 05 Feb 2025

https://github.com/zeyad-azima/opayforme

CVE-2021-43150 Exploit for `opay` android app webview

android exploit flask webview

Last synced: 09 Feb 2025

https://github.com/retr0kr0dy/malloc-bomb

Presenting the latest Linux bomb exploit: not a fork but a malloc-based threat. Delve into the intricacies of this novel vulnerability.

coding cybersecurity denial-of-service dos exploit forkbomb hacking infosec linux malloc pentesting security system-exploitation vulnerability

Last synced: 23 Dec 2024

https://github.com/whokilleddb/cve-2019-15107

CVE-2019-15107 Webmin Exploit in C

cve exploit poc vulnerability

Last synced: 01 Jan 2025

https://github.com/lynk4/cve-2011-2523

Python exploit for vsftpd 2.3.4 - Backdoor Command Execution

cve cve-2011-2523 exploit metasploitable metasploitable-2 metasploitable-3 python vsftpd-exploit

Last synced: 01 Jan 2025

https://github.com/nhas/cve-2024-45337-poc

Proof of concept (POC) for CVE-2024-45337

cve cve-2024-45337 exploit golang hack pentesting poc proof-of-concept ssh

Last synced: 22 Dec 2024

https://github.com/kissssu/ftp-exploit-vsftpd-2.3.4-backdoor

Python script for exploiting a specific vulnerability in vsFTPd 2.3.4.

exploit python3

Last synced: 06 Jan 2025

https://github.com/mxlgv/toaruos-exploits

This is a repository with exploits for ToaruOS.

exploit privelegeescalation toaruos vuln

Last synced: 09 Feb 2025

https://github.com/s1lkys/cve-2021-24884

If an authenticated user who is able to edit Wordpress PHP code in any kind, clicks a malicious link, PHP code can be edited through XSS in Formidable Forms 4.09.04.

exploit formidable wordpress xss

Last synced: 07 Feb 2025

https://github.com/dubniczky/remote-keylogger

A compiled keylogger written in python with logging to a remote host

exploit hack keylogger python server

Last synced: 06 Feb 2025

https://github.com/vaibhavpandeyvpz/dtp-exploit-poc

Simple and single purpose PoC app built using React Native to demonstrate PII leak vulnerability in Delhi Traffic Police's notice payment website.

exploit information leak privacy security vulnerability

Last synced: 02 Jan 2025

https://github.com/netgian/tiktok-shares

Send automatic shares to your favourites tiktok videos!

exploit hacking http python python3 requests tiktok

Last synced: 03 Jan 2025

https://github.com/devvyyxyz/devvyys-scripts

Roblox exploit scripts by Devvyyxyz

exploit roblox-cheat roblox-executor roblox-hack script

Last synced: 09 Feb 2025

https://github.com/franckferman/glpi-htmlawed-cve-2022_35914-poc

Automatic scanning (Shodan) and exploitation (PoC) script for the GLPI htmLawed vulnerability (CVE-2022_35914).

bash exploit glpi poc proof-of-concept python python3 remediation shell shodan vuln vulnerabilities vulnerability vulnerability-detection vulnerability-scanning

Last synced: 19 Jan 2025

https://github.com/mattmoony/shellcode

🐚code for all kinds of occasions or something; very much a constant work in progress + i'm not responsible for whatever you use this for...

assembly binary elf exploit i386 linux malware pe pwn shellcode windows x64

Last synced: 19 Jan 2025

https://github.com/prvvv/chromeforensics

Different code samples for Chrome browser analysis & post exploitation

chrome chrome-devtools exploit forensic forensics forensics-tools hacking password post-exploitation

Last synced: 23 Jan 2025

https://github.com/jenderal92/csrf-exploit-generator

The CSRF Exploit Generator allows users to generate a CSRF exploit form with configurable parameters.

csrf csrf-generator exploit penetration-testing python-27 security-testing-tools web-security

Last synced: 13 Feb 2025

https://github.com/hunthubspace/subscope

SubScope is a Python-based command-line tool that helps you manage domains and subdomains in workspaces using an SQLite database.

automation bugbounty bugbounty-tool database ethical-hacking exploit penetration-testing python sqlite web web-penetration-testing

Last synced: 31 Jan 2025

https://github.com/codingchili/cve-2020-14368

Interactive RCE exploit demo for Eclipse CHE

eclipse-che exploit proof-of-concept vulnerability

Last synced: 12 Feb 2025

https://github.com/langriklol/cve-2020-15227

CVE-2020-15227 exploit

exploit rce security vulnerability

Last synced: 18 Jan 2025

https://github.com/caenjones/codespaces-desktop

Web-based operating system running in Github Codespaces!

bypass codespaces exploit github kasmvnc proxy

Last synced: 11 Nov 2024

https://github.com/rsrdesarrollo/auto-ysoserial

Generate all ysoserial payloads with burp collaborator (or similar)

burp burpsuite exploit java python security security-tools ysoserial

Last synced: 11 Feb 2025

https://github.com/mauricelambert/pywcgishell

This package implement a WebShell for CGI and WSGI server.

cgi-script exploit pypi-package python3 web-attacks webshell wsgi-server

Last synced: 14 Jan 2025

https://github.com/javierolmedo/check-ms17-010

🐞 Simple script in powershell to check ms17-010 vulnerability exploited by ransomware WannaCry

exploit ms17-010 powershell powershell-script script vulnerability wannacry

Last synced: 28 Jan 2025

https://github.com/shamo0/CVE-2022-1388

BIG-IP iControl REST vulnerability CVE-2022-1388 PoC

1388 2022 bash bigip cve cve-2022-1388 exploit f5 icontrol python rest script shell vulnerabilit

Last synced: 23 Oct 2024

https://github.com/pandh4cker/pandagik

Image Magick Exploit for CVE-2016–3714

exploit imagemagick python3 rce

Last synced: 18 Jan 2025

https://github.com/anshvaid4/follinatest

Reference of code has been taken from https://github.com/JohnHammond/msdt-follina/blob/main/follina.py. I have given the explanation of the code and made the code a bit simplified.

cve exploit follina

Last synced: 01 Feb 2025

https://github.com/s1lkys/cve-2021-40101

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

concrete5 cve-2021-40101 exploit xss

Last synced: 01 Feb 2025

https://github.com/hunthubspace/torwatch

TorWatch is a powerful bash script for monitoring the availability of websites through the Tor network. It manages IP address rotation, blocks IP addresses if the site is inaccessible, and logs activities for tracking events.

bash-scripting bugbounty exploit penetration-testing tor web-penetration-testing

Last synced: 31 Jan 2025

https://github.com/SherlockSec/CVE-2020-0601

A Windows Crypto Exploit

cve cve-2020-0601 exploit windows

Last synced: 23 Oct 2024

https://github.com/whokilleddb/CVE-2019-17662

Exploit for CVE-2019-17662 (ThinVNC 1.0b1)

cve cve-2019-17662 exploit poc thinvnc

Last synced: 23 Oct 2024

https://github.com/mauricelambert/webscriptswebshell

Install a WebShell on hardened and deployed WebScripts (using Apache and mod_wsgi).

apache exploit web-attacks webscripts webshell wsgi

Last synced: 24 Jan 2025

https://github.com/zeyad-azima/cve-2022-22733

Apache ShardingSphere ElasticJob-UI Privilege Escalation & RCE Exploit

apache apache2 exploit java shardingsphere vulnerability

Last synced: 09 Feb 2025

https://github.com/qyfashae/memfd_create_2023_exploit

EDUCATIONAL PURPOSES ONLY! Linux/x64 reverse TCP shell exploit via ELF memory processing

exploit linux-exploits python3 shellcode zero-day

Last synced: 01 Feb 2025

https://github.com/gill-singh-a/docker-api-remote-root-shell-exploit

A Simple Python Program that uses Docker Module to communicate with Docker API and gets a Remote Root Shell on the Target Device

docker exploit python ssh

Last synced: 07 Feb 2025

https://github.com/ihsandevs/simplewebshell-php

The Simple Web Shell is a lightweight and user-friendly web-based interface for controlling a website using a single PHP file.

ethical-hacking ethical-hacking-tools exploit hacking php remote-code-execution shell webshell webshells

Last synced: 05 Feb 2025

https://github.com/bstrdlord/mirai-sucks

stop using mirai botnet. better use zig boatnet

boatnet botnet ddos exploit malware mirai qbot shitcode

Last synced: 20 Jan 2025