
obike
Reverse engineering of the oBike protocol communication (BLE and HTTP)

Reverse engineering of the oBike protocol communication (BLE and HTTP)

Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.

HTTP proxy bridge for security testing of remote MCP servers, allowing standard HTTP tools to send JSON-RPC messages and manage sessions.

Nuclei detection template for CVE-2026-41473, an unauthenticated read/write API access flaw in CyberPanel AI Scanner before 2.4.4. Uses two HTTP…

Centralized configuration server for distributed systems with HTTP API, Git-backed storage, property encryption/decryption, and integration with…

Centralized configuration server for distributed systems with HTTP API, encryption/decryption of properties, and support for Git, Vault, JDBC, and…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Knocker, a knock based access control service for your homelab

Discover input surfaces and security issues in compiled .NET assemblies — without running them.

Proof-of-concept exploit for CVE-2026-11103 demonstrating GraphQL rate-limit bypass through batching and field aliases; includes vulnerable Node.js…

Proof-of-concept for CVE-2022-2466 demonstrating unauthenticated GraphQL request context termination in Quarkus/SmallRye, bypassing authorization…

Download Monitor <= 4.7.60 - Sensitive Information Exposure via REST API

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…