-
OnesecICT
- Denver, Colorado
- https://www.linkedin.com/in/francesco-fedele-0702b614b/
- @Frances00832696
Lists (1)
Sort Name ascending (A-Z)
Stars
PoC and vulnerability report for CVE-2025-47827.
A Burp Suite Extension to extract interesting strings (key, secret, token, or etc.) from a webpage.
A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager
Advanced phishing tool:boom: used for session & credential grabbing and bypassing 2FA using man-in-the-middle attack :skull_and_crossbones: with standalone reverse proxy server.
Scrape emails, phone numbers and social media accounts from a website. You can use the found information to gather more information or just find ways to contact the site.
Extract Useful info from SSL VPN Directory Traversal Vulnerability (FG-IR-18-384)
Modified code so that we don´t need to rely on CAB archives
RCE 0-day for GhostScript 9.50 - Payload generator
APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover su…
kal1gh0st / ThreatMapper
Forked from deepfence/ThreatMapperIdentify vulnerabilities in running containers, images, hosts and repositories
📶 Print a QR code for connecting to your WiFi (wificard.io)
kal1gh0st / dirtycow
Forked from firefart/dirtycowDirty Cow is a silly name, but it's a serious Linux kernel problem. According to the Red Hat bug report, "a race condition was found in the way the Linux kernel's memory subsystem handled the copy-…
Method: Privilege Escalation to Administrator and trigger RCE via REST API
A dead simple library to screenshot test React components
Collections of Tools, Bookmarks, and other guides created to aid in OSINT collection
"rsync for cloud storage" - Google Drive, S3, Dropbox, Backblaze B2, One Drive, Swift, Hubic, Wasabi, Google Cloud Storage, Azure Blob, Azure Files, Yandex Files
Pack up to 3MB of data into a tweetable PNG polyglot file.
Instagram-Py Instagram-py performs slick brute force attack on Instagram without any type of password limiting and also resumes your attack in ease. —DeathSec
This python script was written to connect to the remote PBX. Using a telegram bot notifies any calls every 30 minutes.