Skip to content

Latest commit

History

45 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Exploits

Exploits and proof-of-concept code from the team at Hacker House.

FilenameDescription
AirWatchMDMJailbreakBypass.txtBypass jailbreak detection on mobile device management AirWatch for IOS
adobe-psp.tgzAdobe CoolType SING Table "uniqueName" Stack Buffer Overflow PSP bypass (metasploit)
aix53l-libc.cAIX 5.3L libc locale environment handling local root exploit
aix53l-lquerypv.cAIX 5.3L /usr/sbin/lquerypv local root privilege escalation
amanda-amstar.txtAdvanced Maryland Automatic Network Disk Archiver local root privilege escalation exploit
amanda-backup.txtAdvanced Maryland Automatic Network Disk Archiver local root privilege escalation exploit
applejack.cPonyOS 3.0 & below tty ioctl() kernel local root exploit
asus_B1M_projector_root.pngASUS B1M projector remote root command injection (unpatchable)
BTCPE.txtBritish Telecom Huawei UART root access weakness
charybdis.tgzFirefox & IE exploits implant dropper for Windows & Linux
cisco-asa-sslbypass.pyCisco ASA 8.x & below VPN SSL module Clientless URL-list control bypass
cisco-XSS-wget-me.txtCisco IOS 11.x web interface XSS vulnerability
cmd_gpbypass.execmd.exe patched to run even when disabled via Group Policy
cpg15x-dirtraversal.txtCoppermine 1.5.44 & below directory traversal vulnerability
cve-2003-0001.pyCVE-2003-0001.py Etherleak information leak exploit, silently fixed in Cisco ASA PSIRT-0669464365
CVE-2012-4681.tgzOracle Java SE 7 Update 6 & below remote polymorphic exploit (evades PSP)
CVE-2014-0160.pyHeartbleed mass-scanning proof-of-concept tool
cve-2016-1531.shExim 4.84-3 local root exploit
cve-2019-10149.pyExim between 4.87 & 4.91 local root exploit
CVE-2020-0601.xdbXCA database of private keys for trusted CA exploit CVE-2020-0601
CVE-2020-3950.tgzEvilOSX trojan exploit plugin for CVE-2020-3950 VMware Fusion 11.5.2 & below local root
cve-2025-21204.zipIIS exploit files PoC for insecure "inetpub" configuration cve-2025-21204
d3_decimator.txtSedSystems D3 decimator multiple vulnerabilities allow for remote root
dllpack.tgzMS15-051 / MS15-010 exploits with reflective DLL loading support (hacked from public code)
drupal-CVE-2014-3660.pyDrupal XXE libxml2 Services exploit
dtappgather-poc.shdtappgather local root exploit proof-of-concept (EXTREMEPARR)
fluttershy.pyPonyOS 4.0 runtime linker local root exploit
FreeBSD-pftp-dirtraversal.txtPeters Anonymous FTP on FreeBSD directory traversal vulnerability
getlogin.cTru64 V5.1B & below getlogin() kernel information leak
gionight.pyGIO Linux embedded remote root exploit
gns3super-osx.shGNS-3 OS-X local root exploit
goodnight.cLinux kernel 2.6.37 & below denial-of-service exploit CVE-2010-4165
heartbleed-binstatic bin heartbleed exploit (fun trivia, Large Hadron Collider tested with this code)
heartbleed.cHeartbleed exploit using OpenSSL to encrypt the exploit for stealth
heartbleed-keyscan.pyRSA prime factorization exploit for use with heartbleed
hfirixwfcmd.shSGI IRIX <= 6.5.22 WebForce post-auth Remote Command Injection
hfsunsshdx.tgzSunSSH Solaris 10-11.0 x86 libpam remote root exploit CVE-2020-14871
hpwhytry.pyHP XPe embedded devices remote command execution exploit
iis_search.plIIS WebDAV & Indexing service directory traversal attack
inetutils-telnet.txtMultiple BSD based telnet implementations vulnerable to memory corruption.
iPwn.tgzIOS default root user "alpine" exploit to harvest data via SSH
irix-captest.cSGI IRIX <= 6.5.22 capability hijacking "eip" proof-of-concept (SGI XFS)
irix-ftpd-ls.txtSGI IRIX <= 6.5.22 ftpd "/bin/ls" root privilege escalation
irix-mediarecorder.txtSGI IRIX <= 6.5.22 CAP_SCHED_MGT "mediarecorder" privilege escalation
irix-onyx-syssgi.cSGI IRIX <= 6.5.5 syssgi() Onyx IP19/IP21/IP25 kernel information leak exploit
irix-rldx.shSGI IRIX <= 6.4.x run-time linker file creation exploit
irix-runpriv-cap.pngSGI IRIX <= 6.5.x screenshot showing "capabilities" exploit via runpriv
irix-setsockopt.cSGI IRIX <= 6.5.22 kernel mbuf corruption due to integer signedness comparison
irix-syssgi-panic.cSGI IRIX <= 6.5.22 syssgi() SGI_ENUMASHS null ptr kernel panic
irix-tapex.cSGI IRIX <= 6.5.22 "tsdaemon" root arbitrary file creation exploit
irssi-irc-fuzzer.plirssi plugin IRC client fuzzing tool
jackrabbit.tgzRedStar OS 3.0 Naenara browser exploit
jdwp-exploit.txtJava JDWP exploitation for remote code execution
Kronos.tgzJava Signed Applet exploit and web management tool
lbreakout-exploit.clbreakout2 PoC exploit for ARM (drops privileges)
leehseinloong.cppSudoku2 exploit written for Lee Hsien Loong. (.sg PM)
linux-ia32.cLinux Kernel 2.6.32 ia32entry emulation x86_64 exploit
lotus_exp.pyLotus Domino IMAP4 Server Release 6.5.4 win2k remote exploit
mikrotik-jailbreak.txtMikrotik 6.40 & below "telnet" jailbreak exploit
mirc-DoS-Script.iniMirc 6.12 & 6.11 denial-of-service IRC script
mobileiron0day.txtMobileIron Virtual Smartphone Platform local root exploit
MobileIronBypass.tgzMobileIron mobile device management jailbreak detection bypass
MsTelnetServer_NTLM_Guest.txtMicrosoft Telnet Server MS-TNAP Guest Access Restriction Bypass Exploit
MsTelnetServer_NTLM_MutualAuth_ConfigIssueMicrosoft Telnet Server NTLM Mutual Authentication Configuration Issue
mulftpdos.zipServ-U / G6 / WarFTPD denial-of-service exploit in asm
neogeox.txtNeoGeo Gold X games console jailbreak via UART root shell
NetBSD-sa-2016-003-howto-abuse-cpp.pngNetBSD 6.1.5 calendar local root exploit PoC
openbsd-0day-cve-2018-14665.shOpenBSD 6.4 Xorg local root exploit
prdelka-vs-AEP-smartgate.cAEP Smartgate V4.3B arbitrary file download exploit
prdelka-vs-APPLE-chpass.shOS-X 10.6.3 & below chpass arbitrary file creation exploit
prdelka-vs-APPLE-ptracepanic.cOS-X 10.6.1 & below ptrace() mutex handling kernel panic
prdelka-vs-BSD-ptrace.tar.gzNetBSD 2.1 ptrace() local root exploit
prdelka-vs-CISCO-httpdos.zipCisco IOS 12.2 & below HTTP denial-of-service exploit
prdelka-vs-CISCO-vpnftp.cCisco VPN Concentrator 3000 FTP remote exploit
prdelka-vs-GNU-adabas2.txtAdabas D 13.01 SQL injection & directory traversal
prdelka-vs-GNU-adabas.cAdabas D 13.01 local root exploit Linux
prdelka-vs-GNU-chpasswd.cSquirrelMail 3.1 Change_passwd plugin & below local root exploit
prdelka-vs-GNU-citadel.tar.gzCitadel SMTP 7.10 & below remote code execution exploit
prdelka-vs-GNU-exim.cExim 4.43-r2 & below host_aton() local root exploit (Linux)
prdelka-vs-GNU-lpr.cSlackware 1.01 stack overflow local root exploit (Linux)
prdelka-vs-GNU-mbsebbs.cmbse-bbs 0.70.0 & below local root exploit (Linux)
prdelka-vs-GNU-peercast.cPeerCast v0.1216 remote root exploit (linux)
prdelka-vs-GNU-sudo.csudo 1.6.8p9 race condition local root exploit (Linux)
prdelka-vs-GNU-tin.cSlackware 1.01 local root exploit (Linux)
prdelka-vs-HPUX-libc.cHP-UX 11.11 & below libc local root exploit (hppa)
prdelka-vs-HPUX-swask.cHP-UX 11.11 & below swask format string local root exploit (hppa)
prdelka-vs-HPUX-swmodify.cHP-UX 11.11 & below swmodify local root exploit (hppa)
prdelka-vs-HPUX-swpackage.cHP-UX 11.11 & below swpackage local root exploit (hppa)
prdelka-vs-http-fuzz.tar.gzHTTP fuzzing tool & example Savant 3.1 vulnerability
prdelka-vs-LINUS-fchown.tarLinux kernel 2.4.x/2.6.6 & below fchown() file ownership exploit
prdelka-vs-MISC-massftp.tar.gzMass scanning ftp exploiter tool
prdelka-vs-MS-hotmail.txtMicrosoft Hotmail Authentication Bypass vulnerability
prdelka-vs-MS-IE-6.0.2800.1106.XPSP1.rarInternet Explorer 6.0 IFRAME Windows XP exploit
prdelka-vs-MS-rshd.tar.gzWindows RSH daemon 1.8 & below remote exploit
prdelka-vs-MS-winzip.cWinZip 10.0.7245 Win32 & below exploit (the one that angered CERT)
prdelka-vs-SCO-enableSCO OpenServer 5.0.7 enable local root exploit
prdelka-vs-SCO-netwarex.cSCO OpenServer 5.0.7 netware printing local "lp" exploit
prdelka-vs-SCO-ptrace.cSCO Unixware 7.1.3 ptrace() linux kernel emulation local root exploit
prdelka-vs-SCO-tcpdosSCO OpenServer 5.0.7 TCP RST denial-of-service exploit
prdelka-vs-SCO-termshx.cSCO OpenServer 5.0.7 termsh local gid "auth" exploit
prdelka-vs-SGI-xrunprivSGI IRIX 6.5 runpriv local root exploit
prdelka-vs-SUN-sysinfo.cSolaris 10 sysinfo() local kernel memory information leak
prdelka-vs-SUN-telnetd.cSolaris in.telnetd 8.0 & 7.0 remote exploit (sparc)
prdelka-vs-SUN-virtualbox.shSun VirtualBox 3.0.6 local root exploit
prdelka-vs-THC-vmapTHC vmap DoS exploit
prdelka-vs-UNIX-permissions.tar.gzUNIX file permissions generic directory exploit
r00t2.tgzLinux kernel 2.6.29 ptrace_attach() ported to ARM for "google phone"
rainbowdash.tgzPonyOS 3.0 & below kernel ELF loader local root exploit
rarity.cPonyOS 3.0 VFS file permissions local root exploit
raspbian.txtRaspbian vulnerabilities for sgid "games"
redstar2.0-localroot.pngRedStar OS 2.0 local root privilege escalation exploit
redstar3.0-localroot.pngRedStar OS 3.0 local root privilege escalation exploit
rshx.crsh exploit - inject commands via rsh
rsshellshock.pyRedStar OS server BEAM & RSSMON shellshock exploit
s7300cpustart.pySiemens S7-300 PLC CPU start command
s7300stop.pySiemens S7-300 PLC CPU stop command
shoryuken.cLinux kernel 2.6.29 ptrace_attach() local root race condition exploit
skyexp.pySky 1.5 Sagem F@ST 2504 router infoleak & remote command injection
smartmaildos.tgzSmartmail 10.x pop3 & SMTP denial-of-service exploits (in ASM)
sp-email.pySharepoint username enumeration exploit
spiltmilk.cLinux kernel 2.6.37-rc1 & below serial_core TIOCGICOUNT information leak exploit
ssh-dsa1024-rsa2048-keys-CVE-2008-0166.tgzDebian SSH insecure 'prng' SSH keys (released during Manchester riots)
sun-su-bug.txtSolaris 10 'su' local NULL pointer vulnerability CVE-2010-3503
systemd-run-tty.txtSystemd insecure pty allocation vulnerability
telnet_term_0day.pyMultiple BSD-based telnet.c IAC malformed options remote crash
timecrime.cTCP timestamp extensions, information leak exploit (timecrime) from RFC1323/RFC7323
trendmicro_IWSVA_shellshock.pyTrendMicro InterScan Web Security Virtul Appliance shellshock exploit
UNICOS-cray.txtCray UNICOS 9.0 local root vulnerabilities & shellcode PoC
vncscan.pyRealVNC auth bypass CVE-2006-2369 scanner
vxlgiobye.pyVXL Gio Linux remote command execution exploit
w32-fps.txtMicrosoft Frontpage Personal WebServer ver 3.0.2.926 exploit
w32-grpconv.txtWindows XP SP1 grpconv.exe buffer overflow
w32-netcat.tgz"netcat" buffer overflow for Windows 98 exploit
w32-netcat.txt"netcat" buffer overflow for Windows 98 advisory
w32-progman.txtWindows XP "progman" buffer overflow
winnuke2011.shMS11-083 Win7/Vista/2008 ICMP refCount denial-of-service flaw
wysewig.pyWyse embedded XP remote SYSTEM command execution exploit
xclm-exploit.cMicrochip XC local root exploit (Linux) (installed by defcon 26 attendees)
zte-emode.txtZTE Blade Vantage Z839 Emode.APK android.uid.system LPE exploit

These files are available under the 3-clause BSD license.

About

exploits and proof-of-concept vulnerability demonstration files from the team at Hacker House

Resources

Stars

470 stars

Watchers

22 watching

Forks

Releases

Packages

Used by

Contributors

Languages