Category: Exploitation

NodeJS v8 Debugger Command Injection

NodeJS Debugger Command Injection /exploits/multi/misc/nodejs_v8_debugger.rb Metasploit module This module uses the “evaluate” request type of the NodeJS V8 debugger protocol (version 1) to evaluate arbitrary JS and call out to...

WebDavC2: A WebDAV PROPFIND C2 tool

WebDAVC2 LAST/CURRENT VERSION: 0.3 Author: Arno0x0x – @Arno0x0x WebDavC2 is a PoC of using the WebDAV protocol with PROPFIND only requests to serve as a C2 communication channel between an agent, running on...

avoidz

Avoidz: bypass most A.V softwares

Avoidz v1.3 tools to bypass most Anti Virus software   This tool Generate encoded powershell with Metasploit payloads, convert C, C#, py, go Templates to EXE’s Author: Mascerano Bachir [...

isip: Interactive sip toolkit for packet manipulations, sniffing, man in the middle attacks, fuzzing, simulating of dos attacks

isip Interactive sip toolkit for packet manipulations, sniffing, man in the middle attacks, fuzzing, simulating of dos attacks. Install git clone https://github.com/halitalptekin/isip.git cd isip pip install -r requirements.txt Usage Packet...

zirikatu: Fully Undetectable payload generator

zirikatu – Fud Payload generator script Download git clone https://github.com/pasahitz/zirikatu.git Usage Run zirikatu chmod +x zirikatu.sh ./zirikatu.sh Generate FUD payload. Choose a payload Change icon, if you want Start msf listener Get meterpreter session...