All Categories → Security → exploit

Top 343 exploit open source projects

evilMACHO
Malicious use of macho, such as dump-runtime-macho, function-hook.
Gr33k
图形化漏洞利用集成工具
goMS17-010
Simple program for detecting if host(s) are vulnerable to SMB exploit(MS17-010)
SpringBootExploit
项目是根据LandGrey/SpringBootVulExploit清单编写,目的hvv期间快速利用漏洞、降低漏洞利用门槛。
HEVD Kernel Exploit
Exploits pack for the Windows Kernel mode driver HackSysExtremeVulnerableDriver written for educational purposes.
Rage
Rage allows you to execute any file in a Microsoft Office document.
wowned
Authentication bypass for outdated WoW emulation authentication servers
doona
Network based protocol fuzzer
x64dbgpylib
Port of windbglib to x64dbgpy, in an effort to support mona.py in x64dbg.
CamRaptor
CamRaptor is a tool that exploits several vulnerabilities in popular DVR cameras to obtain network camera credentials.
Bash
Collection of bash scripts I wrote to make my life easier or test myself that you may find useful.
discord-bugs-exploits
A Collection of Various Discord Bugs, Exploits, Un-Documented Parts of the Discord API, and Other Discord Related Miscellaneous Stuff.
FastPwn
CTF中Pwn的快速利用模板(包含awd pwn)
IDA Wrapper
An IDA_Wrapper for linux, shipped with an Function Identifier. It works well with Driller on static linked binaries.
padre
Blazing fast, advanced Padding Oracle exploit
spellbook
Framework for rapid development and reusable of security tools
RootMyTV.github.io
RootMyTV is a user-friendly exploit for rooting/jailbreaking LG webOS smart TVs.
CVE-2019-10149
CVE-2019-10149 : A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Exploits
A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction with these exploits.
Scripts-Sploits
A number of scripts POC's and problems solved as pentests move along.
hacker-scripts
⛷ A collection of hacker scripts.
apple-knowledge
A collection of reverse engineered Apple things, as well as a machine-readable database of Apple hardware
vulristics
Extensible framework for analyzing publicly available information about vulnerabilities
CamOver
CamOver is a camera exploitation tool that allows to disclosure network camera admin password.
hack
Kubernetes security and vulnerability tools and utilities.
prl guest to host
Guest to host VM escape exploit for Parallels Desktop
shakeitoff
Windows MSI Installer LPE (CVE-2021-43883)
CVE-2021-41773 CVE-2021-42013
Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE
k8badusb
BadUSB Teensy downexec exploit support Windows & Linux / Windows Cmd & PowerShell addUser exploit
exploit-CVE-2015-3306
ProFTPd 1.3.5 - (mod_copy) Remote Command Execution exploit and vulnerable container
mRemoteNG-Decrypt
Python script to decrypt passwords stored by mRemoteNG
expdev
Vulnerable software and exploits used for OSCP/OSCE preparation
batchql
GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations
go-gtfo
gtfo, now with the speed of golang
Discord-Block-Bypass
Simple script that utilities discord's flaw in detecting who blocked who.
MSF-Self-Defence
Self defense post module for metasploit
CRAX
CRAX: software CRash analysis for Automatic eXploit generation
Ultimate-Guitar-Hack
The first tool to download any Guitar Pro file, including 'Official' from Ultimate Guitar
fusee-nano
A minimalist re-implementation of the Fusée Gelée exploit (http://memecpy.com), designed to run on embedded Linux devices. (Zero dependencies)
PocOrExp in Github
聚合Github上已有的Poc或者Exp,CVE信息来自CVE官网。Auto Collect Poc Or Exp from Github by CVE ID.
DoubleStar
A personalized/enhanced re-creation of the Darkhotel "Double Star" APT exploit chain with a focus on Windows 8.1 and mixed with some of my own techniques
pwn-pulse
Exploit for Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510)
241-300 of 343 exploit projects