
mfoc
Offline nested attack tool that recovers MIFARE Classic authentication keys using known default or user-supplied keys for assessing NFC/RFID card…

Offline nested attack tool that recovers MIFARE Classic authentication keys using known default or user-supplied keys for assessing NFC/RFID card…

PowerShell toolkit for Azure JWT token manipulation, enabling token refresh, switching between service-specific tokens (Graph, Outlook, Teams), and…

Provides library functionality for FIDO2, including communication with a device over USB or NFC.

Post-exploitation tool that abuses Azure Intune/EntraID via C2 agents for PowerShell execution, device queries, and lateral movement without user…

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

True P2P Email on top of Yggdrasil Network for Android

User-friendly Lightweight TPM Remote Attestation over Bluetooth

Opens 1K+ IPs or Shodan search results and attempts to login

Proof-of-concept exploit for CVE-2022-40684 authentication bypass in Fortinet devices, enabling read-only extraction of admin users and LDAP…

Desktop application to register a Signal account and link Signal Desktop without requiring a smartphone, using Signal's cryptographic protocols for…

Device-code phishing server for adversary emulation. Captures Microsoft 365 OAuth tokens via Device Authorization Grant flow. Features relay nodes,…

Python script and Metasploit module that enumerates hidden directories on Siemens BACnet field panels, exploiting an authentication bypass and path…

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

Ephemeral P2P chat over Tor with ChaCha20-Poly1305 end-to-end encryption, automatic hidden service setup, self-destructing invites, and QR code…

Passwordless zero-knowledge authentication fabric using Halo2 PLONK proofs, hardware-bound device ring signatures, and BIP-39 recovery phrases for…

Exploit tool for CVE-2013-6117, targeting Dahua DVR authentication bypass. Scans IP lists concurrently to extract device credentials via HTTP.

More private by default Firefox ESR. Fork of ghostery.

Scanner for Mikrotik RouterOS 0day credential disclosure via Winbox interface. Exploits improper authentication on port 8291/TCP to download user…