Georgia

ClumsyLulz

Elite
@SleepTheGod

Taylor.ChristianNewsome@owasp.org Linkedin.com/in/clumsy codepen.io/ClumsyLulz Youtube.com/Stripped Hackerone.com/DBMS Bugcrowd.com/Sleep

iPhone-SSH-Backdoor. This is a shell script that creates an SSH backdoor on an iPhone.

230

SSH-Remote-Code-Execution. SSH Zero-Day Made By ClumsyLulz

128

Windows. Windows And Ways To Break It

100

Ss7. How to set up and install Ss7 and Sigtran Adapt

39

Windows-Atom-Table-Hijacking. A privilege escalation vulnerability exists in Windows due to a flaw in the implementation of the Atom Table. An attacker could exploit this vulnerability by injecting malicious code into the Atom Table and hijacking a legitimate thread to execute the code in the context of a higher privileged process.

31

Android-Malware. Android devices using ADB via the Shodan API. It prompts the user for a command payload, then establishes TCP connections to devices with open ADB ports. It retrieves outputs like SSH credentials and IMEI numbers, saves SSH credentials to a file, and handles exceptions gracefully while allowing simultaneous device processing through threading.

18

Top-1000-blackhat-tools. 1000 black hat tools Collected From github

17

PNGPayload. Fully automated Python script that creates a PNG image from predefined chunks, encodes it to Base64, and saves both the PNG file and the HTML image tag. The script doesn't require any user input and performs all actions automatically.

15

PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF

15

Dorks. Google Dorking Payloads

13

Android_Backdoor. SSH Backdoor for android

13

ChatGPT. Chat GPT Things by Taylor Newsome

12

BreachForums-Database. This file contains usernames emails and passwords as well as tables

12

TCP-Data-Transfer-Tool. TCP Data Transfer Tool By ClumsyLulz

11

Steganography. Steganography Reverse Shell

10

iPhone. iPhone Exploits

8

Databases. Magnets for databases

8

SteamVacBanBypass. A loader to bypass a vac ban on the steam client.

8

Ss7-Connecting. All packages needed

7

100-000-Common-Passwords. Top 100k common passwords from haveibeenpwnd.com

7

SigPloit-ss7. Java

6

Ultimate-Android. Ultimate Android Forensics and Remote Access Toolkit

6

PowerShell-Keylogger. A KeyLogger In PowerShell That I wrote

6

Android-ADB-Backdoor. Kotlin script that demonstrates how to remotely connect to an Android device using ADB

5

Umbreon-Rootkit. Umbreon Rootkit

5

Flipper_Zero_Badusb_hack5_payloads. hack5 badusb payloads moded for be played with flipper zero

5

OGUser.com-Database-Leak. This file contains usernames emails and passwords as well as tables

5

Android-Things. This was wrote by ClumsyLulz

5

0days. 0day Exploits

5

iPhone_Dump_Kernel. Fully Automated Script for DFU and Kernel Log Dump By Taylor Christian Newsome

5

Linux-System-Clipboard-Hijack. This script provides a convenient way to retrieve and copy basic system information, even without root privileges. It works on Linux machines and leverages built-in tools for safe and reliable operation.

5

Onlyfans. Onlyfans

5

YubiKeyPolicyBypass. The script checks if a YubiKey is connected, configuring its SSH key and adding it to the SSH agent. If not detected, it prompts for insertion and includes a bypass placeholder. It also removes Chrome policies from user-specific ($HOME/.config) and system-wide directories (/etc/opt/chrome).

4

Windows-Scripts. My Windows Automated Scripts

4

SSH-Checker. Super fast ssh scanner to check for a massive list of ipaddresses:passwords by ClumsyLulz

4

restoring-LUKS-headers. Bash script that automates the process described in the provided instructions. This script is designed for backing up, nuking, and restoring LUKS headers with encrypted backups.

4

nmap-cheatsheet. Nmap cheatsheet for penetration testing

4

DiscordExploit. Remote File Inclusion

4

Port-Knocking-Windows. A Windows Port Knocking Script

4

AIVoiceChat. Low latency ai companion voice talk in 60 lines of code using faster_whisper and elevenlabs input streaming

4

BlackArchHarden. Black Arch Linux Harden Script By Taylor Christian Newsome

4

WebsocketInjector. Websocket injector allows you to debug and inject code to any wss:// endpoint Logs every incoming and outgoing WebSocket message, including heartbeat signals.

3

TwitterZeroDay. Download Other Users Profile Data By Taylor Christian Newsome

3

SecLists. SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

3

CTF-CHEATS. Cheat sheet for capture the flag

3

Firewall. Egress Filtering From The Application Layer At The Host Domain Port 443 TLS Protection

3

Twilio-Flooder. Twilio Call Flooder To Call Flood Scammers

3

Macbook-Harden. Macbook Security Harden By Taylor Christian Newsome

3

ChromeSandboxEscape. Proof of concept

3

StickamClone. A flask made version of stickam.com tried my best

3

Onlyfans-Telegram-Leak. Bot Leak Codes

3

Linux. Linux Things

3

Scripts. Random Shit

3

SleepShell. A 64-bit Windows shellcode injector. Targeting explorer.exe, it spawns cmd.exe via CreateProcessA. With dynamic API resolution and robust error handling, this admin-privileged tool showcases sophisticated process injection techniques in a compact package.

2

FFmpeg-Ghost-HLS. This tool generates a malicious AVI file embedding a forged HLS playlist and AES-encrypted payloads crafted to manipulate the behavior of vulnerable FFmpeg instances.

2

Steganography-Lab. AES-256-CBC encryption, LSB steganography, logging, and safe payload for lab use.

2

DoS-Tool. A flask web application for layer 4 xmlrpc dos attacking

2

MyBB-Tool. MyBB XSS payload injection on public-facing pages where no authentication is needed. If the target server does not have these vulnerabilities or the pages don’t exist, the script will still return a 404 or similar response.

2

Mp3-Reverse-Shell. Mp3 Reverse Shell Listener In Python

2

ChromeRCE. Proof of concept for my PowerShell remote code execution

2
60
Apply