pwn2own2020

Browser Exploitation

An exploitation project demonstrating how to chain vulnerabilities in Safari to escalate privilege on macOS

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

GitHub

404 stars
37 watching
58 forks
Language: C++
last commit: over 5 years ago
exploitmacospwn2ownsafari

Related projects:

RepositoryDescriptionStars
rpwnage/pwn-myExploits a vulnerability in iOS 14.5 WebKit to gain jailbreak access649
exp-sky/hitcon-2014-ie-11-0day-windows-8.1-exploitAn exploit for a previously unknown vulnerability in Internet Explorer 11 and Windows 8.1, allowing unauthorized access to the system.25
urule99/jsunpack-nA tool designed to emulate browser behavior and detect vulnerabilities in web-based exploits163
demi6od/smashing_the_browserAn in-depth exploration of browser exploitation techniques and vulnerability discovery446
spencerdodd/kernelpopAutomated framework for discovering and exploiting kernel vulnerabilities on Linux and macOS.687
theori-io/zer0con2018_singiAn exploit demonstrating code execution vulnerabilities in macOS Sierra using Safari and WindowServer121
snyk-labs/exploit-workshopAn interactive workshop to teach exploitation techniques using real-world vulnerabilities in Node.js and Java applications.156
stephenbradshaw/vulnserverA tool designed to help developers learn how to find and exploit buffer overflow bugs in software1,011
r0075h3ll/oralyzerA tool to identify vulnerabilities in web applications by probing for Open Redirections and other types of attacks.758
pyroxenites/boftoolsA collection of tools and techniques for exploiting vulnerabilities in software applications.17
siguza/v0rtexAn exploit tool for iOS Surface vulnerabilities218
firebasky/csrougeA tool that exploits vulnerabilities in web servers to execute arbitrary code9
scumjr/dirtycow-vdsoA Proof-of-Concept for exploiting a vulnerability in the Linux vDSO, allowing arbitrary code execution.492
openscanner/xguardianA security scanner for OSX applications that detects potential vulnerabilities in URL scheme hijack, bundle ID hijack, and keychain hijack.41
arimogi/google-dorksA collection of tools and techniques for exploiting vulnerabilities in Google services45