Giter Site home page Giter Site logo

Welcome to Hacker House open-source releases. All files released by Hacker House are available under a Attribution-NonCommercial-NoDerivatives 4.0 International license unless otherwise explicitly stated. These repositories provide educational content for ethical hacking and cyber security practioners. Use in ANY criminal activity is strictly prohibited and against the terms of the software license agreement. A table is provided here to help navigate.

URL Repository Name Description
backdoors backdoors Tools for maintaining access to systems and proof-of-concept demonstrations.
exploits exploits exploits and proof-of-concept vulnerability demonstration files from the team at Hacker House
shellcode shellcode shellcode are codes designed to be injected into the memory space of another process during exploitation.
tools tools A collection of tools created for computer security research purposes.
documents documents Papers, presentations and documents from the team at Hacker House.
OffensiveLua OffensiveLua Offensive Lua. A project to create Lua hacking scripts for Windows platforms.
AESCrypt AESCrypt AES-256 Microsoft Cryptography API Example.
SignToolEx SignToolEx Hack "signtool.exe" to use expired certificates for code-signing
Marble Marble Framework Marble Framework allows for flexible and easy-to-use obfuscation when developing tools, fixed source from Wikileaks
WMIProcessWatcher WMI Process Watcher A CIA tradecraft technique to asynchronously detect when a process is created using WMI.
Artillery Artillery A CIA technique for UAC bypass which utilizes elevated COM object to write to System32 and an auto-elevated process to execute as administrator for persistence.
Stinger Stinger A CIA technique for UAC bypass that obtains the token from an auto-elevated process, modifies it, and reuses it to execute as administrator. 20% cooler
iscsicpl_bypassUAC iscsicpl_bypassUAC UAC bypass for x64 Windows 7 - 11
CompMgmtLauncher_DLL_UACBypass CompMgmtLauncher_DLL_UACBypass CompMgmtLauncher & Sharepoint DLL Search Order hijacking UAC/persist via OneDrive
Gigabyte_ElevatePersist Gigabyte_ElevatePersist Giga-byte Control Center (GCC) Elevation & Persist
cve-2021-34527 cve-2021-34527 CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation
MsSettingsDelegateExecute MsSettingsDelegateExecute Bypass UAC on Windows 10/11 x64 using ms-settings DelegateExecute registry key.
NoFaxGiven NoFaxGiven Code Execution & Persistence in NETWORK SERVICE FAX Service
hfioquake3_DoS hfioquake3_DoS ioquake3 engine is vulnerable to a remotely exploitable off-by-one overflow
envschtasksuacbypass envschtasksuacbypass Bypass UAC elevation on Windows 8 (build 9600) & above.
ColorDataProxyUACBypass ColorDataProxyUACBypass Exploits undocumented elevated COM interface ICMLuaUtil to trigger UAC bypass. Win 7 & up.
cve-2018-10933 cve-2018-10933 cve-2018-10933 libssh authentication bypass
electionhacking electionhacking Diebold Accuvote-TSx Election Machine Hacking
rebirth rebirth rebirth IOS11 - 11.3.1 jailbreak security research utility
pyongyang_2407 pyongyang_2407 Pyongyang 2407 - Android ROM from North Korea, hardware and booting instructions.

Hacker House's Projects

aescrypt icon aescrypt

AES-256 Microsoft Cryptography API Example Use.

artillery icon artillery

CIA UAC bypass implementation that utilizes elevated COM object to write to System32 and an auto-elevated process to execute as administrator.

backdoors icon backdoors

Tools for maintaining access to systems and proof-of-concept demonstrations.

colordataproxyuacbypass icon colordataproxyuacbypass

Exploits undocumented elevated COM interface ICMLuaUtil via process spoofing to edit registry then calls ColorDataProxy to trigger UAC bypass. Win 7 & up.

documents icon documents

Papers, presentations and documents from the team at Hacker House.

exploits icon exploits

exploits and proof-of-concept vulnerability demonstration files from the team at Hacker House

gigabyte_elevatepersist icon gigabyte_elevatepersist

Giga-byte Control Center (GCC) is a software package designed for improved user experience of Gigabyte hardware, often found in gaming and performance PC's. A UAC elevation vulnerability exists that can be used for persistence in a novel fashion.

hfioquake3_dos icon hfioquake3_dos

ioquake3 engine is vulnerable to a remotely exploitable off-by-one overflow due to a miscalculated array index within the privileged admin console command banaddr. Attacker needs the rcon password to exploit this vulnerability.

marble icon marble

The CIA's Marble Framework is designed to allow for flexible and easy-to-use obfuscation when developing tools.

nofaxgiven icon nofaxgiven

Code Execution & Persistence in NETWORK SERVICE FAX Service

pyongyang_2407 icon pyongyang_2407

Pyongyang 2407 - Android ROM from North Korea, modified to run on WBW5511_MAINBOARD_P2 devices. Releases contains an archived ROM with all needed tools to boot DPRK Android on compatible hardware. This repository contains installation instructions, hardware documentation and exploits for disabling censorship tools of North Korea Android.

rebirth icon rebirth

rebirth IOS11 - 11.3.1 jailbreak security research utility

shellcode icon shellcode

shellcode are codes designed to be injected into the memory space of another process during exploitation.

signtoolex icon signtoolex

Patching "signtool.exe" to accept expired certificates for code-signing.

stinger icon stinger

CIA UAC bypass implementation of Stinger that obtains the token from an auto-elevated process, modifies it, and reuses it to execute as Administrator.

tools icon tools

A collection of tools created for computer security research purposes.

wmiprocesswatcher icon wmiprocesswatcher

A CIA tradecraft technique to asynchronously detect when a process is created using WMI.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.