fuzzlove

Complete public repository index.

GitHub Profile

Disclaimer

All content is provided for authorized security research, defensive testing, and educational purposes only.

Any misuse, unauthorized access, or illegal activity is strictly prohibited. You are solely responsible for how you use these materials.

The author assumes no liability for misuse, damage, service disruption, data loss, or legal consequences resulting from use of this code.

ATutor-2.2.4-Language-Exploit
ATutor 2.2.4 Arbitrary File Upload / RCE (CVE-2019-12169)
Python | updated 2026-02-26
ATutor-Instructor-Backup-Arbitrary-File
ATutor 2.2.4 'Backup' Remote Command Execution (CVE-2019-12170)
n/a | updated 2026-02-26
buffer_overflows
Various bufferoverflows made or examined while I was in the process of studying.
Python | updated 2024-09-17
byosi
Bring Your Own Scripting Interpreter - Custom Shell (PHP)
PowerShell | updated 2024-12-30
CallBackCodeExecution-v1
CallBackCodeExecution v1 - Vanilla Series
C | updated 2026-04-29
Cisco-ASA-FTD-Web-Services-Traversal
CVE-2020-3452 - Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) traversal
Python | updated 2026-01-10
Cisco-UCS-Manager-2.2-1d-Remote-Command-Execution
Cisco Bug: CSCur90888 - Cisco UCS Manager Remote Command Execution Vulnerability
Python | updated 2021-02-05
coruna
The leaked exploit toolkit for various iOS versions
JavaScript | updated 2026-03-12
curlshell
reverse shell using curl
Python | updated 2024-04-17
default-http-login-hunter
Login hunter of default credentials for administrative web interfaces leveraging NNdefaccts dataset.
Lua | updated 2024-04-16
Downgrade-Checker-iOS
 iOS Downgrade Party Checker ✅ 🥳
Python | updated 2026-05-07
eLabFTW-1.8.5-EntityController-Arbitrary-File-Upload-RCE
eLabFTW 1.8.5 'EntityController' Arbitrary File Upload / RCE (CVE-2019-12185)
Python | updated 2024-08-12
frameless-bitb
A new approach to Browser In The Browser (BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented by login pages like Microsoft and the use with Evilginx.
CSS | updated 2025-01-15
FUDforum-XSS-RCE
FUDForum 3.0.9 - XSS / Remote Code Execution (CVE-2019-18873, CVE-2019-18839)
JavaScript | updated 2022-07-16
fuzzlove
n/a | updated 2026-05-13
GopherSSRF
Gopher HTTP requests (POST/GET)
Python | updated 2025-10-26
GPPFire
GPP Fire - AutoLogins & Others
Python | updated 2025-04-21
impacket
Impacket is a collection of Python classes for working with network protocols.
Python | updated 2026-02-26 | archived
interactsh
An OOB interaction gathering server and client library
Go | updated 2026-02-26 | archived
lazychicken
lazychicken.sh - A simple external IP check that utilizes multiple sources.
Shell | updated 2024-06-08
limbos-gate
Hell's Gate, but make it 32-bit!
C | updated 2026-02-26 | archived
linpeas
Shell | updated 2024-06-03
macOS-Audit-Agent
Mac Audit Agent is a macOS security auditing and monitoring tool that helps identify system risks, suspicious activity, and configuration weaknesses. It provides clear findings, baseline change detection, and actionable recommendations while keeping all data local to the device.
Python | updated 2026-05-09
malk
Demonstrate calling a kernel function and handle process creation callback against HVCI
C++ | updated 2026-02-26 | archived
MBE
Course materials for Modern Binary Exploitation by RPISEC
C | updated 2024-03-05
OneRuleToRuleThemStill
A revamped and updated version of my original OneRuleToRuleThemAll hashcat rule
n/a | updated 2024-04-11
OWASP-Testing-Guide-v5
The OWASP Testing Guide includes a "best practice" penetration testing framework which users can implement in their own organizations and a "low level" penetration testing guide that describes techniques for testing most common web application and web service security issues.
n/a | updated 2019-08-30
p12cracker
Bruteforce p12 files for fun
Python | updated 2026-05-08
PEzor
Open-Source Shellcode & PE Packer
C | updated 2024-12-25
PowerShell-Reverse-Shell-Generator
Obfuscated, FUD Simple PowerShell Reverse Shell One-Liner
Python | updated 2024-07-02
PowrShhh
Simple yet effective PS SC loader.
PowerShell | updated 2025-10-29
privesc-lin
privesc stuff for linux
Shell | updated 2024-06-03
privesc-win
privesc tools for windows
PowerShell | updated 2024-04-25
ReverseGoShell
A Golang Reverse Shell Tool With AES Dynamic Encryption
Go | updated 2022-06-02
Shaco
Shaco is a linux agent for havoc
C | updated 2026-02-26
shellGo
A Microsoft windows x86_64 Golang shellcode tester that includes example calc.exe shellcode.
Go | updated 2022-06-10
Sickle
Shellcode development tool
Python | updated 2019-09-18
SigFlip
SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.
C# | updated 2026-02-26 | archived
SkyC2
A basic python c2 server
Python | updated 2025-10-29
social-engineering-vector-analysis
Technical analysis and Proof of Concepts (PoCs) for common web-based execution vectors, including ClickFix and FileFix methodologies. This repository maps these techniques to MITRE ATT&CK T1204.004 for defensive research.
HTML | updated 2026-02-26
soplanning-1.52-exploits
SOPlanning 1.52.00 CSRF/SQLi/XSS (CVE-2024-33722, CVE-2024-33724)
n/a | updated 2024-05-07
SparstanBoogie
Exploit chain utilizing directory traversal and iOS restore to overwrite protected files.
Python | updated 2026-05-23
SuperMega
Stealthily inject shellcode into an executable
Python | updated 2026-02-26 | archived
SystemFunction032-Case-Studies
SystemFunction032 Research
C++ | updated 2026-02-26
TeamViewer-Password-Decrypt
TeamViewer Password Decrypter
Python | updated 2024-04-25
WindowsD
Disable DSE and WinTcb (without breaking DRM)
C | updated 2025-03-29
Zipper
A shellcode runner that runs shellcode from a password protected zip file.
C | updated 2026-02-26
Zippy
C# Shellcode Runner (In-Memory GZip)
C# | updated 2026-02-26