
ADTrapper
Hunt Smarter, Hunt Harder

Hunt Smarter, Hunt Harder

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

Technical analysis and PoC of CVE-2026-52824: default APP_SECRET in the Kimai Docker image enabling unauthenticated login link forgery. Affects <=…

Proof-of-concept exploit toolkit for SharePoint ToolPane RCE (CVE-2025-53770) with scanner, payload analysis, and multiple exploitation methods for…

Detailed CVE-2026-51788 advisory for a DoS vulnerability in cleverange_auth v0.1.10, with technical analysis, CVSS scoring, and mitigation guidance…

Docker-based lab for reproducing Keycloak CVE-2026-18963, including vulnerable version setup, realm seeding, and source-level workflow analysis with…

Isolated educational lab simulating CVE-2025-4679 OAuth credential exposure. Learn offensive and defensive security through hands-on exercises,…

Detailed analysis of CVE-2024-27198: authentication bypass in JetBrains TeamCity leading to remote code execution, with code-level explanation and…

Demonstrates CVE-2025-22235 Spring Boot authentication bypass via EndpointRequest.to() misconfiguration. Includes environment setup, reproduction…

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162025) in Copilot, including impact analysis, affected versions, and…


An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

Exploitability PoC for CVE-2026-43512 (Apache Tomcat Digest Authentication Bypass)

Penetration tests guide based on OWASP including test cases, resources and examples.

Implementation of the Google Zero-Knowledge library for Identity Protocols.


CVE-2024-38200 & CVE-2024-43609 - Microsoft Office NTLMv2 Disclosure Vulnerability

Demos for the Blackhat USA 2022 talk "Taking Kerberos to the Next Level"