Google Compute Engine (GCE) VM takeover via DHCP flood - gain root access by getting SSH keys added by google_guest_agent
☆535Jul 30, 2021Updated 5 years ago
Alternatives and similar repositories for gcp-dhcp-takeover-code-exec
Users that are interested in gcp-dhcp-takeover-code-exec are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- CVE-2020-15368, aka "How to exploit a vulnerable driver"☆515Apr 14, 2022Updated 4 years ago
- This repo gives an overview of some GCP metadata API attack and defend patterns☆79Mar 23, 2020Updated 6 years ago
- ☆703Nov 27, 2024Updated last year
- Reverse proxies cheatsheet☆1,886Nov 4, 2023Updated 2 years ago
- Automated GKE Kubelet Impersonation and Cluster Secret Stealer via kube-env☆102Sep 10, 2019Updated 6 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- This is a PoC exploit for CVE-2020-8559 Kubernetes Vulnerability☆54Jul 23, 2020Updated 6 years ago
- ☆2,525Jan 2, 2023Updated 3 years ago
- How to exploit a double free vulnerability in 2021. Use After Free for Dummies☆1,387Jan 31, 2025Updated last year
- Collections of Orange Tsai's public presentation slides.☆762Jan 1, 2025Updated last year
- Kubernetes POC for utilizing write mount to /var/log for getting a root on the host☆100Nov 18, 2020Updated 5 years ago
- Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.☆827Jun 12, 2021Updated 5 years ago
- A container analysis and exploitation tool for pentesters and engineers.☆685Sep 27, 2023Updated 2 years ago
- ☆169May 20, 2021Updated 5 years ago
- NAT Slipstreaming allows an attacker to remotely access any TCP/UDP services bound to a victim machine, bypassing the victim’s NAT/firewa…☆1,984Jan 14, 2023Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Catalog Red Team techniques that cause popups in various macOS versions☆16Nov 18, 2024Updated last year
- Client-Side Prototype Pollution Tools☆90Sep 21, 2021Updated 4 years ago
- Correlates serviceaccounts and pods to the permissions granted to them via rolebindings and clusterrolesbindings.☆36May 18, 2022Updated 4 years ago
- Electron Research☆71Feb 9, 2022Updated 4 years ago
- A DNS rebinding attack framework.☆1,315Jul 21, 2026Updated last month
- Prototype Pollution and useful Script Gadgets☆1,645Jan 27, 2024Updated 2 years ago
- CVE-2021-1675 Detection Info☆214May 20, 2023Updated 3 years ago
- ☆1,199Sep 2, 2022Updated 3 years ago
- This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-…☆4,623Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆699Jul 4, 2022Updated 4 years ago
- Issues with WebSocket reverse proxying allowing to smuggle HTTP requests☆401Aug 15, 2024Updated 2 years ago
- Simple patcher tool to turn off TLS handshake validation in golang binaries☆11Apr 23, 2022Updated 4 years ago
- Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock☆7,160Mar 12, 2024Updated 2 years ago
- Viewgen is a ViewState tool capable of generating both signed and encrypted payloads with leaked validation keys☆668Feb 1, 2025Updated last year
- Exploit for CVE-2020-3952 in vCenter 6.7☆274Apr 16, 2020Updated 6 years ago
- Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.☆653Nov 21, 2019Updated 6 years ago
- RCE 0-day for GhostScript 9.50 - Payload generator☆543Sep 8, 2021Updated 4 years ago
- C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527☆1,999Jul 20, 2021Updated 5 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- WinDbg script to spoof origin and url of a renderer process in Chrome☆25Dec 2, 2020Updated 5 years ago
- ☆452Oct 3, 2024Updated last year
- Proof of concept code for Datadog Security Labs referenced exploits.☆449Updated this week
- This repo has been replaced by https://www.cloudvulndb.org☆723Jun 29, 2022Updated 4 years ago
- These are tools we released with our 2020 defcon/blackhat talk https://www.youtube.com/watch?v=Ml09R38jpok☆174Feb 6, 2025Updated last year
- Client Side Prototype Pollution Scanner☆530Sep 17, 2022Updated 3 years ago
- kCTF is a Kubernetes-based infrastructure for CTF competitions. For documentation, see☆792Mar 25, 2026Updated 5 months ago