PoC for GhostCommit Attack: Steal secrets via a pull request pointing to an image
☆32Aug 19, 2026Updated last month
Alternatives and similar repositories for ghostcommit
Users that are interested in ghostcommit are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- 基于Pocsuite3、goby编写的漏洞poc&exp存档☆12Nov 19, 2023Updated 2 years ago
- This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by …☆28Jul 15, 2026Updated 2 months ago
- ☆24Feb 27, 2026Updated 7 months ago
- 第八届 “强网杯” 全国网络安全挑战赛☆21Nov 11, 2024Updated last year
- ☆12Jun 12, 2023Updated 3 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Post release curated articles (MarkDown & Corrections)☆19Sep 22, 2026Updated last week
- https://heyitsas.im/posts/cifswitch☆67Jun 1, 2026Updated 4 months ago
- Bug bounty focused JavaScript security analysis for crawling web assets, source maps, and secret discovery☆64Aug 1, 2026Updated 2 months ago
- Threat Hunting Malware Infrastructure☆12Dec 3, 2023Updated 2 years ago
- Vulnerability and security bulletins related to Palantir software products.☆13Mar 3, 2023Updated 3 years ago
- UnFuck Windows Setup☆25Aug 16, 2024Updated 2 years ago
- A bug bounty tool for bypassing 401/403 access restrictions and testing endpoint accessibility.☆54Updated this week
- My dotfiles macOS / Linux (Ubuntu, Debian, Arch Linux)☆19Jun 9, 2026Updated 3 months ago
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆14Feb 16, 2026Updated 7 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Malware, tooling, logs, IOCs and intelligence☆58Aug 31, 2026Updated last month
- ☆12May 25, 2026Updated 4 months ago
- Binary Ninja Plugins to work with Unpac.Me unpacking service☆13Apr 24, 2025Updated last year
- A critical severity Remote Code Execution (RCE) vulnerability (CVE-2023-22527) was discovered in Confluence Server and Data Center.☆22Jan 23, 2024Updated 2 years ago
- Pure-Rust Android decompiler and security-audit suite. DEX → Java, Hermes → JavaScript. Cross-layer taint across the React Native bridge.…☆32Jun 11, 2026Updated 3 months ago
- ☆56Aug 21, 2026Updated last month
- Sherlock Mail is a sophisticated email intelligence tool that leverages artificial intelligence and machine learning to provide comprehen…☆16Dec 6, 2024Updated last year
- This repository provides Python tools for training and using the TEGNet neural network to predict thermoelectric generator (TEG) performa…☆20Nov 14, 2025Updated 10 months ago
- Okta Data Collector for BloodHound Community☆17Sep 23, 2026Updated last week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Dynamic binary translator for x86 binaries☆38Apr 7, 2023Updated 3 years ago
- 一个类似sqlmap的RCE自动化工具☆52Jan 27, 2025Updated last year
- WebStrike 是一套以 Chromium 系浏览器扩展(Manifest V3) 为受控端点的指挥与控制(C2)套件。与传统以进程/驱动为主的 C2 相比,其工作重心落在 浏览器安全域:在合规授权与攻防演练场景下,可显著降低与终端 EDR 在 进程注入、驱动、内核回调…☆87Jul 8, 2026Updated 2 months ago
- EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.☆69May 11, 2026Updated 4 months ago
- Skeleton (but pronounced like Peloton): A Zero-Click RCE exploit for CVE-2021-0326☆21Mar 16, 2022Updated 4 years ago
- CVE-2026-45250: FreeBSD 14.4 setcred kernel buffer overflow (LPE)☆22Jul 23, 2026Updated 2 months ago
- Windfall - Unauthenticated RCE exploit chain for Windmill & Nextcloud Flow (CVE-2026-29059). Path traversal + credential leak + PostgreSQ…☆18Apr 7, 2026Updated 5 months ago
- ☆15Mar 27, 2026Updated 6 months ago
- ☆28Oct 4, 2018Updated 7 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.☆62Sep 11, 2026Updated 3 weeks ago
- Smuggling C2 comms through links previews☆18Jun 17, 2026Updated 3 months ago
- Automatically deploying Mythic C2 in Azure using Terraform☆25Jul 3, 2026Updated 3 months ago
- Documentation for the SecureDrop project☆28Updated this week
- A single-page resume template completely typeset with HTML & CSS.☆20Aug 15, 2018Updated 8 years ago
- Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with C…☆18Apr 12, 2026Updated 5 months ago
- Implementation of KlezVirus' silent moonwalk approach for payloads☆18Feb 13, 2026Updated 7 months ago