Skip to content
Change the repository type filter

All

    Repositories list

    • SQL Injection login as admin challenge - single button deploy, just set your custom CTF Flag in the setup process!
      HTML
      5201Updated Jan 1, 2024Jan 1, 2024
    • cve

      Public
      Gather and update all available and newest CVEs with their PoC.
      MIT License
      854000Updated Feb 16, 2022Feb 16, 2022
    • PoCs

      Public
      A list of CVE's with Proof of Concepts
      HTML
      2000Updated Jun 17, 2021Jun 17, 2021
    • UhOh365

      Public
      A script that can see if an email address is valid in Office365 (user/email enumeration). This does not perform any login attempts, is unthrottled, and is incredibly useful for social engineering assessments to find which emails exist and which don't.
      Python
      103000Updated Oct 23, 2019Oct 23, 2019
    • XSS payloads for exploiting Markdown syntax
      179000Updated Aug 16, 2019Aug 16, 2019
    • lan-js

      Public
      Probe LAN devices from a web browser.
      JavaScript
      Other
      7000Updated May 28, 2019May 28, 2019
    • Hash collisions
      Python
      192000Updated Feb 23, 2019Feb 23, 2019
    • A library for parsing .DS_Store files and extracting file names
      Python
      MIT License
      56000Updated Oct 16, 2018Oct 16, 2018
    • Hacking slot machines.
      C++
      34200Updated Sep 20, 2018Sep 20, 2018
    • botnets

      Public
      This is a collection of #botnet source codes, unorganized. For EDUCATIONAL PURPOSES ONLY
      C++
      747200Updated Sep 2, 2018Sep 2, 2018
    • dref

      Public
      DNS Rebinding Exploitation Framework
      JavaScript
      70000Updated Aug 22, 2018Aug 22, 2018
    • Like nmap for mapping wifi networks you're not connected to, plus device tracking
      Python
      MIT License
      189200Updated Aug 13, 2018Aug 13, 2018
    • HTML
      MIT License
      5000Updated May 31, 2018May 31, 2018
    • GPON

      Public
      Exploit for Remote Code Execution on GPON home routers (CVE-2018-10562) written in Python. Initially disclosed by VPNMentor (https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/), kudos for their work.
      Python
      69000Updated May 10, 2018May 10, 2018
    • Demo of a Vue.js app that mixes both clientside templates and serverside templates leading to an XSS vulnerability
      PHP
      22000Updated Feb 26, 2018Feb 26, 2018
    • Chrome extension and Express server that exploits keylogging abilities of CSS.
      CSS
      432000Updated Feb 20, 2018Feb 20, 2018
    • dns2proxy

      Public
      Offensive DNS server
      Python
      163000Updated Jan 1, 2018Jan 1, 2018
    • dnsd

      Public
      Dynamic authoritative name server
      JavaScript
      Apache License 2.0
      67000Updated Sep 20, 2017Sep 20, 2017
    • intercepting kali router
      Shell
      79100Updated Aug 25, 2017Aug 25, 2017
    • SecGen

      Public
      Create randomly insecure VMs
      Ruby
      GNU General Public License v3.0
      376000Updated Aug 16, 2017Aug 16, 2017
    • A collection of various awesome lists for hackers, pentesters and security researchers
      Creative Commons Zero v1.0 Universal
      9.1k500Updated Aug 6, 2017Aug 6, 2017
    • jaqen

      Public
      Jaqen - Simple DNS rebinding
      Go
      BSD 2-Clause "Simplified" License
      15000Updated Jul 25, 2017Jul 25, 2017
    • Crack WPA/WPA2 Wi-Fi Routers with Airodump-ng and Aircrack-ng/Hashcat 🖧
      MIT License
      1.1k000Updated Jul 24, 2017Jul 24, 2017
    • Bella

      Public
      A pure python, post-exploitation, data mining tool and remote administration tool for macOS.
      Python
      MIT License
      128100Updated Feb 11, 2017Feb 11, 2017
    • Pillage web accessible GIT, HG and BZR repositories
      Shell
      59000Updated Jan 19, 2017Jan 19, 2017
    • PHP
      Other
      3200Updated Jan 5, 2017Jan 5, 2017
    • SQL Injection bypass auth code challenge - single button deploy, just set your custom CTF Flag in the setup process!
      HTML
      3200Updated Jan 2, 2017Jan 2, 2017
    • Hack your friend's online MMORPG game - specific focus, php file upload scripts
      PHP
      1410010Updated Jan 2, 2017Jan 2, 2017
    • CTF-XSS

      Public
      XSS cookie stealing challenge - single button deploy, just set your custom CTF Flag in the setup process!
      PHP
      8710Updated Jan 1, 2017Jan 1, 2017
    • SQL Truncation challenge - single button deploy, just set your custom CTF Flag in the setup process!
      PHP
      2100Updated Jan 1, 2017Jan 1, 2017