
sshamble
Research tool that scans SSH services for authentication bypasses, timing leaks, weak keys, and post-session exposures, with JSON output and analysis.

Research tool that scans SSH services for authentication bypasses, timing leaks, weak keys, and post-session exposures, with JSON output and analysis.

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

SwiftNIO SSH is a programmatic implementation of SSH using SwiftNIO

🔐 Secure, real-time monitoring dashboard for OpenClaw AI agents. Auth, TOTP MFA, cost tracking, live feed, memory browser and more.

COFF file (BOF) for managing Kerberos tickets.

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

Python exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass. Includes Shodan and FOFA dorks for vulnerable instance discovery.

Post-Exploitation EVTX Analyzer for BloodHound Mapping

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

Vatilon-based IP camera firmwares issue Session-Id tokens without verifying credentials, allowing attackers to obtain sessions and retrieve plaintext…

Proof-of-concept exploit for CVE-2025-12028 demonstrating CSRF-based OAuth token theft in WordPress IndieAuth plugin, enabling unauthorized API…

SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)

Session-scoped TOTP rate limiting permits repeated verification attempts

A small PoC for the Keycloak vulnerability CVE-2023-0264

EUVD-2026-89950 Improper Handling of URL Encoding (Hex Encoding) (CWE-177)