
zttp
Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

Security research — PoC for local root privilege escalation on macOS Mavericks 10.9.

HardeningKitty - Checks and hardens your Windows configuration

High-performance multi-protocol AAA server for RADIUS, DHCPv4/v6, DNS, TACACS+, and VMPS, centralizing network authentication, authorization, and…

This is a simple Shiro-basic project .Just for pentest env

General-purpose cryptography library and SSL/TLS toolkit providing encryption, decryption, X.509 certificate management, and secure communication…

Open-source toolkit implementing SSL/TLS protocols and a full-strength cryptography library with encryption, decryption, certificate management, and…

Robust toolkit implementing TLS/SSL protocols and a full-strength cryptographic library for encryption, decryption, certificate creation, and secure…

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

DSC resources to simplify administration of certificates on a Windows Server.

OAuth and OAuth2 support library for Spring Security, enabling secure API authentication and authorization for consumer and provider implementations…

General-purpose cryptography library implementing SSL/TLS protocols, symmetric/ asymmetric ciphers, message digests, and X.509 certificate handling…

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

CVE-2026-0257 - PAN-OS

A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass

Public Disclosure

Python exploit script for CVE-2024-1709, an authentication bypass vulnerability in ConnectWise ScreenConnect. Adds a new administrative user to the…

Educational lab demonstrating CVE-2022-39227 JWT authentication bypass in python-jwt. Step-by-step attack against vulnerable and patched Flask apps…