TecR0c / exploits
This repository hosts PoC exploits for vulnerabilities I've discovered, provided for education and to highlight the importance of system security.
☆19Updated last year
Related projects ⓘ
Alternatives and complementary repositories for exploits
- This script is designed to exploit a heap buffer overflow vulnerability in a socks5 proxy server.☆22Updated 8 months ago
- ☆13Updated last year
- Cryptanalysis of the DAO exploit & Multi-Stage Attack☆20Updated 7 months ago
- 「💥」CVE-2022-33891 - Apache Spark Command Injection☆27Updated 2 years ago
- aiohttp LFI (CVE-2024-23334)☆22Updated 8 months ago
- CVE-2023-20198 & 0Day Implant Scanner☆31Updated last year
- Exploits of different CVE IDs (CVE-2021-37910, CVE-2021-40288, CVE-2021-41435, CVE-2021-41436, CVE-2021-41437, CVE-2021-41441, CVE-2021-4…☆16Updated 2 years ago
- A folder to serve tools from during PT/Red Team engagements. Contains common executables and scripts for privesc, recon, pivoting and CVE…☆15Updated 8 months ago
- Keycloak admin API allows low privilege users to use administrative functions☆23Updated last month
- pdfkit <0.8.6 command injection shell. The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sa…☆22Updated last year
- DLink DIR-846 Authenticated Remote Code Execution☆18Updated last year
- Exploit Proof-of-Concept code for XAMPP v3.3.0 — '.ini' Buffer Overflow (Unicode + SEH)☆14Updated last year
- Presentation materials for my Black Hat USA 2022 Briefing and Arsenal talks☆64Updated 2 years ago
- Repo for all my exploits/PoCs☆27Updated 2 months ago
- Automated HTTP Request Repeating With Burp Suite☆34Updated last year
- Exploit for elevation of privilege vulnerability in QuickHeal's Seqrite EPS (CVE-2023-31497).☆18Updated last year
- MyBB 1.8.32 - Chained LFI Remote Code Execution (RCE) (Authenticated) python exploit script...☆15Updated last year
- Tomcat backdoor based on CS blog☆27Updated last year
- This tool is useful in case you want to evade the detection based on simple rules when trying to dump the SAM, SYSTEM or SECURITY hives u…☆10Updated 2 years ago
- 「🚪」Linux Backdoor based on ICMP protocol☆60Updated 8 months ago
- A straightforward tool for exploiting SMTP Smuggling vulnerabilities.☆15Updated 4 months ago
- Make an Linux Kernel rootkit visible again.☆43Updated last month
- Updated Exploit - pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)☆23Updated 3 months ago
- CVE-2024-29895 PoC - Exploiting remote command execution in Cacti servers using the 1.3.X DEV branch builds☆21Updated 6 months ago
- OSINT tool abusing SecurityTrails domain suggestion API to find potentially related domains by keyword and brute force.☆26Updated last year
- 👻 [PoC] CSV+ 0.8.0 - Arbitrary Code Execution (CVE-2022-21241)☆24Updated 2 years ago