
vuln-bank-mobile
A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Local-first encrypted password vault for Android with Master Password access, Recovery Key support, Autofill integration, and portable encrypted…

Proof-of-concept for CVE-2026-7671, demonstrating OTP brute-force on Tornet Scooter Android app due to missing rate limiting on /TwoFactor endpoint.

CVE-2025-5154: Proof-of-concept for unencrypted local storage of authentication tokens, PII, and KYC data in the PhonePe Android app, enabling…

A "plugin" for Android Java to allow asking the user about SSL certificates

An intentionally vulnerable Android Application to demonstrate various vulnerabilities that airses in Android Components.

PoC for CVE-2026-0073, an Android ADB authentication bypass enabling network attackers to connect to previously paired devices over wireless…

Frida-based proof-of-concept demonstrating authentication bypass in Telegram Android by hooking SharedConfig.checkPasscode to always return true,…

Security research PoC for CVE-2026-0073: ADB authentication bypass verification


CVE-2026-0073 - ADB Wireless Mutual Authentication Bypass PoC

A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.

a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket

Manage x509 certificates on PIV-enabled YubiKeys, generate keys and certificate requests, and sign or verify git commits and files.

ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade, convert, dissect and shuck authentication token based…

Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

Exploit for CVE-2017-13872 that escalates privileges by changing the root password on vulnerable systems. Requires execution and provides new root…