k0x-offsec / CDPwn
CDPwn is a python script designed to capture screenshots of files via the Chrome DevTools Protocol (CDP), a technique useful for privilege escalation when the CDP service runs with root permissions.
☆11Updated 5 months ago
Related projects ⓘ
Alternatives and complementary repositories for CDPwn
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆25Updated 9 months ago
- List of some AD tools I frequently use☆43Updated last month
- This repository serves as a curated resource for OffSec's OSEP (PEN-300) certification preparation, containing useful links, materials, a…☆14Updated last week
- Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")☆59Updated 11 months ago
- Speedy probe-based UDP service scanner☆42Updated last week
- CVE-2023-34362: MOVEit Transfer Unauthenticated RCE☆63Updated 7 months ago
- CVE-2023-21554 Windows MessageQueuing PoC,分析见 https://www.zoemurmure.top/posts/cve_2023_21554/☆54Updated last year
- Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit☆73Updated last month
- CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.☆37Updated 6 months ago
- Exploit for CVE-2024-20767 - Adobe ColdFusion☆33Updated 7 months ago
- ☆15Updated 2 years ago
- A repository of tools developed while studying for OSEP. The contents here are not part of courseware but some tools, i wrote as an exten…☆0Updated 5 months ago
- cve-2022-42889 Text4Shell CVE-2022-42889 affects Apache Commons Text versions 1.5 through 1.9. It has been patched as of Commons Text ver…☆37Updated 2 years ago
- Authentication Bypass in GoAnywhere MFT☆64Updated 9 months ago
- PoC for CVE-2022-23940☆10Updated 2 years ago
- Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers.☆36Updated last year
- Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10☆14Updated last year
- Exploit for the CVE-2024-5806☆40Updated 4 months ago
- Proof of conept to exploit vulnerable proxycommand configurations on ssh clients☆18Updated 11 months ago
- ☆38Updated 10 months ago
- PoC repository for CVE-2023-29007☆32Updated last year
- ☆55Updated 7 months ago
- .NET deserialization hunter☆73Updated 4 months ago
- HTTP flyover tool based on the httpx library by ProjectDiscovery☆34Updated 2 months ago
- CVE-2024-27956 WordPress Automatic < 3.92.1 - Unauthenticated SQL Injection☆18Updated 6 months ago
- The purpose of this repo is to share my research☆14Updated 11 months ago
- Proof of Concept Exploit for CVE-2024-9464☆42Updated last month
- Exploits targeting vBulletin.☆76Updated last year