
SMSOTPBOT
OTP BOT Bypass SMS verifications from Paypal, Instagram, Snapchat, Google, 3D Secure, and many others...

OTP BOT Bypass SMS verifications from Paypal, Instagram, Snapchat, Google, 3D Secure, and many others...

Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security…

Go-based PoC for Ghost CMS Content API SQL injection (CVE-2026-26980). Verifies vulnerability, extracts admin credentials and API secrets, and…

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

Automated exploit for Ghost CMS CVE-2023-40028 that authenticates to the admin API, uploads a symlinked ZIP, and reads arbitrary host files from the…

Active Directory relay attack detection and enumeration tool. Scans for NTLM relay opportunities, detects CVE-2025-33073, CVE-2025-54918,…

Proof-of-concept script demonstrating CVE-2023-40028 Local File Inclusion in Ghost CMS via symlink file upload, enabling authenticated attackers to…

Arbitrary file read in Ghost-CMS allows an attacker to upload a malicious ZIP file with a symlink.

Linux post-exploitation tool for deploying persistent backdoors/rootkits with process hiding, Metasploit session unlimited, and automatic…

Python-based proof-of-concept exploit for CVE-2023-40028, a symlink upload vulnerability in Ghost CMS enabling authenticated arbitrary file read via…

Blind SQL injection exploit for Ghost CMS (CVE-2026-26980) targeting unauthenticated Content API to extract credentials, API keys, and database…

Proof-of-concept exploit for CVE-2023-40028 enabling authenticated arbitrary file read in Ghost CMS via symlink upload. Includes interactive shell…

Proof-of-concept exploit for CVE-2023-40028, an arbitrary file read vulnerability in Ghost CMS, allowing authenticated users to read host files via…

Lightweight Fabric-based script to remotely check Linux hosts for the GHOST vulnerability (CVE-2015-0235) via SSH, supporting password and key…

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

A Directory Traversal attack (also known as path traversal) aims to access files and directories that are stored outside the intended folder.

Android post-exploitation framework leveraging ADB for remote device access, shell control, and automated exploitation during penetration testing…

Lightweight RAT providing silent remote command-line access, hidden file download/execution, and persistence mechanisms for Windows systems.…