This is your work, valued
Student
CVE-2024-4367-PoC. CVE-2024-4367 & CVE-2024-34342 Proof of Concept
★ 203CVE-2024-24787-PoC. CVE-2024-24787 Proof of Concept
★ 5iptime-a1004v-emulation-script. iptime a1004v emaulation shell script using qemu
★ 2CVE-2023-32961. PoC of CVE-2023-32961
★ 2slack-todo-bot. Slack Todo Bot
★ 2LOURC0D3.
★ 2gh-discus.
★ 1CVE-2024-39700-PoC. CVE-2024-39700 Proof of Concept
★ 1Jekyll-with-Notion-Template. This is the repository for https://lourcode.kr/posts/Jekyll-%EA%B8%B0%EB%B0%98-Github-Pages%EC%99%80-Notion-Page-%EC%97%B0%EB%8F%99.
★ 1CVE-2023-29439. PoC of CVE-2023-29439
★ 1LOURC0D3.github.io. https://lourcode.kr
★ 1WebKit. Home of the WebKit project, the browser engine used by Safari, Mail, App Store and many other applications on macOS, iOS and Linux.
★ 10kida-multi-mcp. Multi-instance IDA Pro MCP server — analyze multiple binaries simultaneously through a single MCP endpoint.
★ 366Mole. 🐹 Clean, uninstall, analyze, optimize, and monitor your Mac from the terminal.
★ 61kiOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201. CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS. Exploitation bypassed Blastdoor, enabled kernel escalation (CVE-2025-31201), and allowed token theft until patched in iOS 18.4.1 (Apr 16, 2025).
★ 198WeKnora. Open-source LLM knowledge platform: turn raw documents into a queryable RAG, an autonomous reasoning agent, and a self-maintaining Wiki.
★ 19kXcodeAnyTroll. Run app from Xcode, without any code signature, but with any entitlements. Based on TrollStore.
★ 159patchfuzz. PatchFuzz: Fuzzing for JavaScript Engine Incomplete Security Patches
★ 23Pishi. Pishi is a code coverage tool like kcov for macOS.
★ 76aws-bare-metal-kvm-demo. Shell
★ 33bsddrivers. FreeBSD Device Drivers
★ 2PassiveFuzzFrameworkOSX. This framework is for fuzzing OSX kernel vulnerability based on passive inline hook mechanism in kernel mode.
★ 229KextFuzz. Code of KextFuzz: Fuzzing macOS Kernel EXTensions on Apple Silicon via Exploiting Mitigations (USENIX Security'23)
★ 96sample-images. Sample image files for ImageGlass
★ 7Xtrace. Trace Objective-C method calls by class or instance
★ 1.8kp0tools. Project Zero Docs and Tools
★ 849Driver-Security-Analyzer. Driver Security Analyzer
★ 54PDFMathTranslate. [EMNLP 2025 Demo] PDF scientific paper translation with preserved formats - 基于 AI 完整保留排版的 PDF 文档全文双语翻译,支持 Google/DeepL/Ollama/OpenAI 等服务,提供 CLI/GUI/MCP/Docker/Zotero
★ 36kInferno. Apple Silicon device emulator.
★ 3.8ksystembag.kb. Collection of tools to decrypt and parse systembag.kb file
★ 10XcodeRootDebug. Allow Xcode to start a custom debugserver with root privileges to debug iOS apps.
★ 263security-pcc. Private Cloud Compute (PCC)
★ 1kwinafl-harness. harness for fuzzing with winafl. both public and my own which i have released.
★ 58NauthNRPC. Python
★ 12dualra1n. Dualboot ios 15 and 14 iDevices to 15-13.6
★ 297SEPROMPanicDecrypt. SEPROM Panic Decrypt Tool written in python
★ 29Keka. The macOS & iOS file archiver
★ 7.1kInspectiveC. objc_msgSend hook for debugging/inspection purposes.
★ 720a7-sep-bug. a7 sep bug
★ 54papers_and_slides.
★ 277memctl. An iOS kernel introspection tool.
★ 272iphone-dataprotection. Some useful tools for a iOS Forensics.
★ 40autodecrypt. Tool to decrypt 64 bits iOS firmware images (iBoot/LLB/iBSS/iBEC).
★ 196iOS-Internals-and-Security-Testing. iOS is Apple's proprietary operating system that runs on the iPhone, iPod Touch and iPad. A lot of components are specific to iOS. Here are key features of the iOS hardware and software security architecture and guide how to test your applications.
★ 152kemon. An Open-Source Pre and Post Callback-Based Framework for macOS Kernel Monitoring.
★ 398pdfium-binaries. 📰 Binary distribution of PDFium
★ 1.4kfrp. A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.
★ 108krathole. A lightweight and high-performance reverse proxy for NAT traversal, written in Rust. An alternative to frp and ngrok.
★ 14kbore. 🕳 bore is a simple CLI tool for making tunnels to localhost
★ 11kNN-SVG. Publication-ready NN-architecture schematics.
★ 5.7kHyperPill. C++
★ 65Mac_Vuln.
★ 131apple-knowledge. A collection of reverse engineered Apple things, as well as a machine-readable database of Apple hardware
★ 1.4kxnu-qemu-arm64. C
★ 1.5kktrw. An iOS kernel debugger based on a KTRR bypass for A11 iPhones; works with LLDB and IDA Pro.
★ 698sephelper. IDA loader to help with SEPROM reverse engineering.
★ 36iBoot64helper. IDAPython loader to help with AArch64 iBoot, iBEC, and SecureROM reverse engineering
★ 264KeychainAccess. Simple Swift wrapper for Keychain that works on iOS, watchOS, tvOS and macOS.
★ 8.3kida_kcpp. An IDAPython module for enhancing c++ support on top of ida_kernelcache
★ 142ida_kernelcache. An IDA Toolkit for analyzing iOS kernelcaches.
★ 143tamarin-firmware. C
★ 494CVE-2024-38063. poc for CVE-2024-38063 (RCE in tcpip.sys)
★ 694CVE-2024-6387. Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (CVE-2024-6387)
★ 188cve-2024-6387-poc. a signal handler race condition in OpenSSH's server (sshd)
★ 495CVE-2024-22274-RCE. PoC - Authenticated Remote Code Execution in VMware vCenter Server (Exploit)
★ 45buzzer. Go
★ 477marp-vscode. Marp for VS Code: Create slide deck written in Marp Markdown on VS Code
★ 2.1kCVE-2023-24871. pocs & exploit for CVE-2023-24871 (rce + lpe)
★ 51ioctlance. A tool that is used to hunt vulnerabilities in x64 WDM drivers
★ 469ImHex. 🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
★ 54kquals-2024. Source code for the DEF CON 32 CTF Qualifiers.
★ 75decomp2dbg. A plugin to introduce interactive symbols into your debugger from your decompiler
★ 809ARC-Browser-Address-Bar-Spoofing-PoC. CVE-2024-25733 | ARC Browser Address Bar Spoofing PoC - iOS/iPadOS
★ 6tracer. Signature-based Static Analysis for Detecting Recurring Vulnerabilities
★ 51ghidriff. Python Command-Line Ghidra Binary Diffing Engine
★ 796binkit. Binary Reverse Engineering Data Science Kit
★ 88starred. Create and maintain your own Awesome-style list from GitHub stars!
★ 1.9kidawasm. IDA Pro loader and processor modules for WebAssembly
★ 372COMRaceConditionSeeker. Python
★ 11FullPowers. Recover the default privilege set of a LOCAL/NETWORK SERVICE account
★ 700docs. various docs (that are interesting, or not, depending on the point of view...)
★ 148deauth. deauth 어택입니다.
★ 2SyscallTables. Windows NT Syscall tables
★ 1.5kawesome-vm-escape. share some useful archives about vm and qemu escape exploit.
★ 604CVE-2023-27326. VM Escape for Parallels Desktop <18.1.1
★ 170MTMR. 🌟 [My TouchBar My rules]. The Touch Bar Customisation App for your MacBook Pro
★ 4.3kghidra-python-vscode-skeleton. Ghidra Headless Python Script VScode Skeleton
★ 3kAFL. A fuzzer for full VM kernel/driver targets
★ 805unmask_jemalloc. De Mysteriis Dom jemalloc
★ 66OSX-KVM. Run macOS on QEMU/KVM. With OpenCore + Monterey + Ventura + Sonoma support now! Only commercial (paid) support is available now to avoid spammy issues. No Mac system is required.
★ 23kFishFuzz. AFL/AFL++ version FishFuzz
★ 99PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
★ 80kpublic-writeup. CTF write-ups by Plaid Parliament of Pwning
★ 805macOSSandboxInitializationBypass. App sandbox escapes for macOS
★ 31trigger-webhook-from-notion. Add a button that can trigger a POST webhook in Notion.so's table.
★ 75morethan-log. 😎 A static blog using notion database
★ 2.3ksophomore. Java
★ 1hackthebox-writeups. Writeups for HacktheBox 'boot2root' machines
★ 2.1kctfd-auth-discord-bot. ctfd 인증 디스코드 봇
★ 1exploits. Exploits I've written at some point.
★ 4CTFdScraper. Simple scraper for automating challenges gathering from a CTFd platform
★ 49bruteforce. Brute forcing scripts for bad CTF problems
★ 48LOURC0D3.github.io. https://lourcode.kr
★ 1GhidraLog4Shell. Java
★ 30how2heap. A repository for learning various heap exploitation techniques.
★ 8.8kPoC-CVE-2021-41773. Python
★ 52LOURC0D3.
★ 2Fuzzing101. An step by step fuzzing tutorial. A GitHub Security Lab initiative
★ 3.8klog4jpwn. log4j rce test environment and poc
★ 311log4j-shell-poc. A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
★ 1.9k