
rewerse-engineering
Rewe API reverse engineering in Go

Rewe API reverse engineering in Go


ArmourBird CSF - Container Security Framework

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Free honeypot token scanner for Ethereum, Polygon & Arbitrum. Detect scam tokens before you buy. Instant analysis of smart contracts using 13…

Lightweight Python library for obfuscating JWT payload values using XOR encryption with timestamp-based keys, preventing plaintext decoding of…

The simple PoC of CVE-2023-27587

WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction

[CVE-2020-17518] Apache Flink RESTful API Arbitrary File Upload via Directory Traversal

PHP 8.4+ security library (mirror)

A command-line tool to check if passwords have been exposed in data breaches using the Have I Been Pwned (HIBP) API.

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

A Hacker's E-learning App for Tamil People

PoC for CVE-2026-21020, demonstrating Protobuf Any-type polymorphic deserialization where attacker-controlled type_url can lead to logic bugs, RCE,…

PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)

Enrolled agent can smuggle arbitrary OpenSearch _bulk operations via DataValue.index. GHSA-ff9g-85jq-r3g3. Draft

gRPC-Go RBAC Authorization Policy Bypass via Missing `:path` Slash (Auth Bypass)