The repository is a 'Kompromat' project that collects private keys, certificates, and key parameters for auditing cryptographic key weaknesses. Files are organized into categories such as firmware, localhost certificates, local roots, RFC examples, software tests, and test vectors, with contribution guidelines emphasizing key revocation and responsible disclosure.
Updated 2026-09-04 05:40:04 +00:00
OSIRIS is a production-grade OSINT platform that provides situational awareness across multiple intelligence domains. Built with Next.js 16 and MapLibre GL, it aggregates live flight tracking, CCTV, earthquakes, and news into a single GPU-accelerated interface.
Updated 2026-09-04 04:32:08 +00:00
Generate tags for the milliways-security repositories
Updated 2026-09-04 01:30:32 +00:00
SecLists is a comprehensive collection of security tester's wordlists including usernames, passwords, URLs, and fuzzing payloads used during penetration testing.
Updated 2026-09-03 11:15:18 +00:00
Matrix bot for Milliways
Updated 2026-09-03 09:03:31 +00:00
Aikido Safe Chain is a cross-platform security tool that intercepts npm and PyPI package downloads via a local proxy to block malware and enforce minimum package age policies for developer workstations and CI/CD environments.
Updated 2026-09-03 08:48:31 +00:00
FalconFlank is a 0day privilege-escalation exploit against the Crowdstrike Falcon Sensor on Windows that abuses the Office malicious-macro remediation feature. It races a mount-point reparse point and replaces bcrypt.dll to inject a malicious DLL that Falcon loads while processing a malicious Office compound file.
Updated 2026-09-03 03:44:38 +00:00
TrustMeBro is a Go-based red-team tool that intercepts command-line tools used by LLM coding agents (Codex, Claude Code, pi) via PATH shims. It fabricates or rewrites tool output such as DNS query results to test whether AI agents can be manipulated into bypassing guardrails with fabricated tool evidence.
Updated 2026-09-01 06:55:59 +00:00
A proof-of-concept exploit for a pre-auth remote code execution in Apache Log4j 2. The FilteredObjectInputStream deserialization allowlist is bypassed by hiding a Commons Collections CC6 gadget chain inside a java.rmi.MarshalledObject, which Log4j's LogEventProxy unwraps using an unfiltered ObjectInputStream.
Updated 2026-08-26 15:50:37 +00:00
A containerised lab reproducing Apache log4j2 issue #4255, a deserialization allowlist bypass in FilteredObjectInputStream via java.rmi.MarshalledObject. It demonstrates a silent, application-conditional RCE where a gadget hidden inside a MarshalledObject's opaque bytes is deserialized on an unfiltered stream. No CVE is assigned.
Updated 2026-08-26 09:22:23 +00:00
This repository is a proof-of-concept for CVE-2026-18963, an unauthenticated account-takeover in Keycloak versions 26.0.0 through 26.7.1. It contains a Python 3 exploit script demonstrating a reset-credentials flow bypass, a Docker Compose lab environment, and a Keycloak realm configuration file for testing.
Updated 2026-08-26 08:13:39 +00:00
This repo holds PoCs for Linux kernel LPEs (Fragnesia CVE-2026-46300, PinTheft, DirtyDecrypt, MariaDB, PostgreSQL CVE-2026-14669), QEMUtiny CXL RCE, Dolphin DSP-HLE guest-to-host escape, FirefUXSS iOS XSS, TerraMaster TossUp Redis/NFS RCE, THORChain finality bypass, NEAR Intents storage exhaustion, Rabby credential leak, Miden node flaws, and Redis UAF RCE (CVE-2026-23479).
Updated 2026-08-25 18:19:05 +00:00
V12 security team PoC repository covering Linux kernel LPEs (Fragnesia CVE-2026-46300, PinTheft), DirtyDecrypt, FirefUXSS iOS UXSS, TossUp TerraMaster Redis RCE, QEMUtiny CXL escape, Dolphin DSP-HLE RCE, MariaDB RCE, Thorchain attestation bypass, PostgreSQL TZ heap overflow RCE (CVE-2026-14669), plus NEAR Intents, Rabby, and Miden Node findings.
Updated 2026-08-25 18:19:05 +00:00
An exploit for CVE-2026-62911, a pre-authentication remote code execution in Microsoft Exchange Server. It abuses the missing Extended Protection on the HTTP.sys-hosted MRSProxy endpoint, relaying a machine account's NTLM hash to write an ASPX webshell and achieve full SYSTEM takeover. Part of an Orange Tsai Pwn2Own Berlin 2026 chain.
Updated 2026-08-22 04:49:54 +00:00
Matrix bot for Milliways
Updated 2026-08-22 00:01:35 +00:00
XSS2Shell is a pre-authentication reflected XSS vulnerability in WordPress wp-login.php (CVE-2026-64638) that chains to full RCE against logged-in administrators via OAuth app-password abuse, REST API page creation, and plugin upload.
Updated 2026-08-21 13:31:56 +00:00
This repository provides threat hunting resources, including Nexthink advanced hunting queries, Azure Sentinel rules, and EDR block rules to detect potential malware downloads, credential theft, and exploitation of vulnerabilities like Exchange ProxyShell and PaperCut CVEs across Windows environments.
Updated 2026-08-14 08:46:10 +00:00
Skitter-creek-bath-salts is a hardware-level exploit for AMD Family 16h CPUs that scrambles DRAM address translations by flipping bits in the memory controller (MCT/DCT). This creates aliases to protected memory regions including PSP private DRAM, SMRAM, C6 idle-state stash, and CPU microcode, unlocking everything invisible even to ring-0.
Updated 2026-08-13 16:59:38 +00:00
ShieldBreak is a Windows Defender bypass exploit demonstrating a patch bypass for the RoguePlanet vulnerability (CVE-2026-50656). It uses Cloud Files API callbacks during file scanning to achieve 100% success rate on Windows 11 and Server 2025.
Updated 2026-08-11 19:46:00 +00:00