Morocco

Abdelkarim Mouchquelita

Elite
@mchklt

i'm Abdelkarim Mouchquelita i'm 21, Python Ninja, CTF Player and I Break Into Machines When They Refuse to Have A Peaceful Conversation.

CVE-2025-30406. CVE-2025-30406 ViewState Exploit PoC

90

Nmap-Bomber. Port scanning is crucial in recon, but running it manually on big scopes? Nope. That’s why I made Nmap Bomber a Python script that runs fast and furious parallel nmap scans on your subdomains.

43

auth-bypass. auth-bypass is a collection of common techniques and payloads used to bypass authentication mechanisms during web penetration testing. It includes methods targeting login forms, headers, and logic flaws, making it a handy reference for CTFs, labs, and real-world assessments. Ideal for bug bounty hunters and ethical hackers looking to streamline the

12

LMOJAWIB-ofppt-langues. Lmojawib kayjawb 3la b2 f francais d ofppt-langues

10

csrf-file-upload-poc. This PoC showcases how an attacker can exploit a CSRF vulnerability to upload a file to a victim's account without their knowledge. The attack leverages the victim's session or performs unauthorized actions on their behalf.

9

Ping-Pong. A Bash script to monitor the status of hosts. It allows you to add, remove, display, clean duplicate entries, and count unique IP addresses. Use long (--add, --clean) or short (a, c) command options for convenience while tracking host status efficiently.

9

cryptoghost. cryptoghost is a script for decrypt or decode your data .

7

Hash_it. hasher is a script for hash your data

6

my_beginning_articles.

4

mailto_scraper. mailto_scraper its a simple script for scrape mails from html pages.

3

Frappe-ErpNext-AuthBypass-SSTItoRCE. A critical vulnerability in ERPNext’s Jinja templating implementation allows SSTI attacks that result in remote code execution. Combined with an account hijacking flaw, this enables unauthenticated attackers to fully compromise the system.

2

browsPEAS. browsPEAS is a lightweight script that analyzes browser history and bookmarks to extract URLs with parameters and detect sensitive data like tokens or credentials. It’s useful for CTFs, labs, and real-world pentests where browser artifacts can reveal valuable attack paths. Works with sqlite3 or falls back to basic shell tools, and can be used stand

1

mosquito_monitorer. `mosquito_monitorer` is a lightweight Python script that connects to an MQTT broker, listens to all topics, filters out irrelevant messages (specifically those with a payload length of exactly 29), and logs only meaningful data into a timestamped text file.

1
13
Apply