NextSniper
exploitNext.js exploitation scanner — CVE-2025-29927 & CVE-2025-55182 middleware bypass + RSC traversal modules. Confirmed RCE on production AWS EC2.
Arsenal
Every tool is pure Python stdlib — no pip, no vendoring. Colored terminal output, JSON/JSONL export, stdin pipeline support and severity-based exit codes, so they chain straight into subfinder | httpx | tool --stdin.
Next.js exploitation scanner — CVE-2025-29927 & CVE-2025-55182 middleware bypass + RSC traversal modules. Confirmed RCE on production AWS EC2.
Rootless Android pentest suite via Frida Gadget injection on Termux. 8-layer SSL pinning bypass, secret scanner, schema-aware deeplink fuzzer, autopilot.
Next.js / Vercel bundle intelligence — chunk harvesting, source-map recovery, endpoint & secret extraction with an HTML report per target.
POST endpoint discovery + HTML form parsing with body-parameter injection across SQLi / XSS / SSTI / RCE / LFI / CRLF / Open Redirect.
CVE-2026-21643 scanner for FortiClientEMS — PostgreSQL injection via Site header, CAST-trick error extraction, time-based blind fallback.
Shodan REST asset mapper — multi-query harvest, DNS domain API, IP↔port↔domain↔cert correlation and httpx target generation.
JavaScript source intelligence — endpoint, secret and sink discovery across bundled front-end assets.
Fast HTTP probe with fingerprinting, tech detection and pipeline-friendly JSONL output.
FortiSandbox unauthenticated OS command injection scanner (CVE-2026-39808) with canary-based false-positive prevention.