jhftss / POC
A public collection of POCs & Exploits for the vulnerabilities I discovered
☆356Updated 8 months ago
Related projects ⓘ
Alternatives and complementary repositories for POC
- ☆320Updated 5 months ago
- An automatic Blind ROP exploitation tool☆190Updated last year
- Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit☆267Updated 11 months ago
- A script to automate privilege escalation with CVE-2023-22809 vulnerability☆148Updated last year
- Pwn2Own Vancouver 2023 Ubuntu LPE exploit☆156Updated last year
- Massive Mobile Security Framework☆253Updated last month
- Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing☆130Updated 6 months ago
- Automated script to convert and push Burp Suite certificate in Android, and modify Android's IP table to redirect all traffic to Burp Sui…☆109Updated last year
- Work in progress...☆310Updated 4 months ago
- Tips on how to write exploit scripts (faster!)☆419Updated 4 months ago
- LPE exploit for CVE-2023-21768☆416Updated last year
- LPE exploit for CVE-2023-21768☆482Updated last year
- POC for CVE-2022-39952☆266Updated last year
- CVE-2023-4911 proof of concept☆163Updated last year
- A PoC code for JSON Smuggling technique to smuggle arbitrary files through JSON☆112Updated 7 months ago
- Proof-of-Concept for CVE-2023-38146 ("ThemeBleed")☆189Updated last year
- out-of-bounds write in Fortinet FortiOS CVE-2024-21762 vulnerability☆125Updated 8 months ago
- Slides and videos from my public speeches / conferences☆70Updated 3 weeks ago
- Advanced exploits that I wrote for Pwn2Own competitions and other occasions☆161Updated 7 months ago
- Microsoft SharePoint Server Elevation of Privilege Vulnerability☆228Updated last year
- ☆209Updated 7 months ago
- Kraken, a modular multi-language webshell coded by @secu_x11☆515Updated 9 months ago
- A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager☆341Updated 2 years ago
- Black box fuzzer for web applications☆404Updated 4 months ago
- Oversecured Vulnerable iOS App☆214Updated 10 months ago
- Oracle VirtualBox Elevation of Privilege (Local Privilege Escalation) Vulnerability☆215Updated 6 months ago
- CVE-2024-3400 Palo Alto OS Command Injection☆150Updated 7 months ago
- Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration test…☆338Updated this week
- ☆132Updated 2 years ago
- MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.☆492Updated 3 months ago