IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - auth-tls-match-cn injection, CVE-2025-1098 – mirror UID injection -- all available.
☆97May 6, 2025Updated last year
Alternatives and similar repositories for ingressNightmare-CVE-2025-1974-exps
Users that are interested in ingressNightmare-CVE-2025-1974-exps are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Zero Privilege Kubernetes Penetration Testing problem solver☆274Jul 29, 2025Updated 11 months ago
- Kubernetes has its “ADCS” -- How To Backdoor a Kubernetes in silence and more persistent?☆41Nov 16, 2025Updated 8 months ago
- ☆53Mar 25, 2025Updated last year
- a golang based dotnet ysoserial poc generation tool. Operated by cursor and reproduce from metasploit☆15Nov 12, 2025Updated 8 months ago
- CVE-2022-25845(fastjson1.2.80) exploit in Spring Env!☆108Nov 7, 2024Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ghost-bits-encoder 是一个面向 Woodpecker 的辅助插件,围绕 Ghost Bits / Unicode 高位包装思路,提供通用编解码、JSON 相关编码、URL 相关编码以及若干专项辅助能力。☆52May 15, 2026Updated 2 months ago
- ☆79Nov 22, 2024Updated last year
- Use the Netlogon Remote Protocol (MS-NRPC) to dump the target hash.☆62Feb 25, 2025Updated last year
- Here is a common vulnerability when Kubernetes Controller designed.☆10Dec 11, 2023Updated 2 years ago
- Go 代码混淆工具,使用 AST (抽象语法树) 技术实现跨文件的代码混淆,同时保证混淆后的代码可编译和可执行。☆177Jul 2, 2026Updated 2 weeks ago
- PoC Exploit for the NTLM reflection SMB flaw.☆709Feb 18, 2026Updated 5 months ago
- Weaponized VSCode Extensions☆20May 7, 2026Updated 2 months ago
- Open Source XSS exploitation tool. using http proxy to access the browser which executed js. [Engineering Experimental]☆42Nov 22, 2024Updated last year
- 多组件客户端☆74May 1, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A tool specifically designed for Kubernetes environments aims to efficiently and automatically discover hidden vulnerable APIs within clu…☆105May 20, 2025Updated last year
- Some ReadObject Sink With JDBC☆245May 8, 2024Updated 2 years ago
- command execute without 445 port☆59Feb 25, 2022Updated 4 years ago
- Post-exploit a compromised etcd, gain persistence and remote shell to nodes.☆94May 7, 2024Updated 2 years ago
- Exploits a flaw in Remote Desktop Plus by monitoring and decrypting temporary .rdp files in %localappdata%/Temp, revealing credentials us…☆18Jul 3, 2025Updated last year
- Active Directory Authentication Library☆96May 12, 2026Updated 2 months ago
- Let sliver use msf payload!☆25Mar 23, 2025Updated last year
- PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared ima…☆181May 7, 2026Updated 2 months ago
- PolicyKit CVE-2021-3560 Exploit (Authentication Agent)☆116May 2, 2022Updated 4 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- ☆313Feb 27, 2025Updated last year
- Proof of Concept for Authentication Bypass in JetBrains TeamCity Pre-2023.11.4☆36Mar 5, 2024Updated 2 years ago
- 构造字节在ASCII范围内的jar☆142Feb 14, 2022Updated 4 years ago
- portreuse reuseport 端口复用☆61Aug 27, 2023Updated 2 years ago
- 利用代理驱动绕过JDBC Attack检测☆146Jun 15, 2025Updated last year
- ☆30Mar 26, 2026Updated 3 months ago
- This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).☆249Mar 26, 2025Updated last year
- 用于快速启动tabby 分析漏洞或者gadget的环境☆93Jul 14, 2025Updated last year
- Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit☆83Oct 7, 2024Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆36Mar 4, 2025Updated last year
- 《深入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Explo…☆590Feb 7, 2026Updated 5 months ago
- A VSCode Workspace based hacking environment utils. Starting your Note-Driven Hacking experience.☆111Aug 21, 2025Updated 10 months ago
- PoC & Exploit for CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"☆215Jul 6, 2025Updated last year
- 不那么一样的 Java Agent 内存马☆290Nov 27, 2023Updated 2 years ago
- ☆108Dec 10, 2025Updated 7 months ago
- ☆248May 5, 2024Updated 2 years ago