k0x-offsec / CDPwnLinks
CDPwn is a python script designed to capture screenshots of files via the Chrome DevTools Protocol (CDP), a technique useful for privilege escalation when the CDP service runs with root permissions.
☆14Updated last year
Alternatives and similar repositories for CDPwn
Users that are interested in CDPwn are comparing it to the libraries listed below
Sorting:
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆34Updated last year
- ☆18Updated last year
- Deserialization payload generator for a variety of .NET formatters☆176Updated 2 months ago
- Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit☆83Updated last year
- ☆54Updated 3 months ago
- CVE-2023-33733 reportlab RCE☆119Updated 2 years ago
- Dockerized POC for CVE-2022-42889 Text4Shell☆76Updated 3 years ago
- CVE-2024-41570: Havoc C2 0.7 Teamserver SSRF exploit☆74Updated last year
- List of some AD tools I frequently use☆56Updated 2 months ago
- Apache commons text - CVE-2022-42889 Text4Shell proof of concept exploit.☆56Updated 2 years ago
- ☆68Updated last year
- ☆73Updated last year
- ☆37Updated 10 months ago
- ☆13Updated 5 years ago
- Burp Extension to add additional functionality for pentesting websocket based applications☆103Updated 5 months ago
- Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)☆91Updated last year
- Authentication Bypass in GoAnywhere MFT☆65Updated 2 years ago
- CVE-2023-34362: MOVEit Transfer Unauthenticated RCE☆64Updated last year
- Golden collection of weak passwords☆71Updated last year
- Exploit for CVE-2024-20767 - Adobe ColdFusion☆34Updated last year
- ysoserial.net docker image☆28Updated last year
- Proof of conept to exploit vulnerable proxycommand configurations on ssh clients☆19Updated 2 years ago
- PoCs of RCEs against open source C2 servers☆91Updated last year
- Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")☆57Updated 2 years ago
- CVE-2023-21554 Windows MessageQueuing PoC,分析见 https://www.zoemurmure.top/posts/cve_2023_21554/☆57Updated 2 years ago
- CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.☆42Updated last year
- Tool to enable blind sql injection attacks against websockets using sqlmap☆66Updated 9 months ago
- Exploits targeting vBulletin.☆75Updated 2 years ago
- Apache Superset Auth Bypass (CVE-2023-27524)☆11Updated 2 years ago
- Exploit AD CS misconfiguration allowing privilege escalation and persistence from any child domain to full forest compromise☆124Updated 2 years ago