
two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal
Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

Magisk module for Android 14 that adds user-installed CA certificates to the system's Conscrypt trust store, enabling HTTPS interception with proxy…

Intentionally vulnerable Android banking app for practicing mobile security testing. Covers OWASP Mobile Top 10 with hardcoded credentials, insecure…

Android client for Nextcloud with a focus on SQL injection vulnerability (CVE-2019-5454) analysis and exploitation testing.

Reporte técnico sobre vulnerabilidad crítica de Xiaomi

PoC Exploiting SQL Injection in Android's Download Provider in Sort Parameter (CVE-2019-2196)

PoC Exploiting SQL Injection in Android's Download Provider in Selection Parameter (CVE-2019-2198)

Conference talk materials and slides demonstrating exploitation of insecure navigation patterns in third-party Android App Lockers, with a focus on…

Proof-of-concept exploit for Same-Origin Policy bypass in Samsung Internet Browser for Android, demonstrating a cross-origin data access…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Hacking tools pack & backdoors generator.

PoC Exploiting SQL Injection in Android's Download Provider (CVE-2018-9493)

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through the Remote Debugging…

Android deeplink, Intent, and WebView bridge assessment helper for ethical hacking

Exploit for CVE-2020-6514 targeting WebRTC SCTP memory corruption in Android applications. Uses Frida to hook native functions and alter SCTP packets…

Documentation of an Android app debug interface leakage vulnerability (CVE-2023-27703) enabling XSS and information disclosure via repeated invalid…

Proof-of-concept exploit for CVE-2019-6447 in ES File Explorer, enabling local network attackers to extract device info, files, and launch apps via…

Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another…