
swicc
A framework for creating smart cards (ICC-based cards with contacts).

A framework for creating smart cards (ICC-based cards with contacts).

Proof-of-concept exploit for Progress WhatsUp Gold SQL injection authentication bypass (CVE-2024-6670). Includes root cause analysis and automated…

Package ldapserver implements LDAP Server

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

Certificate authority issuing short-lived code-signing certificates tied to OpenID Connect identities, enabling verifiable software supply chain…

Exploit module for Apache JSPWiki CVE-2022-46907, targeting a Java-based wiki platform with JAAS security integration. Provides vulnerability…

Java-based wiki platform with JAAS security integration, access control, and detailed configuration auditing. Includes documentation for…

WebUI for AAA

Exploit module for Apache JSPWiki CVE-2019-10077, targeting a Java-based wiki platform with JAAS authentication and access control. Enables…

Exploit testing repository for Apache JSPWiki CVE-2019-10078, demonstrating a cross-site scripting vulnerability in a Java-based wiki platform with…

Java-based wiki platform with detailed access control and JAAS security integration, provided as a vulnerable version for security testing and CVE…

Fully transparent SSH, HTTPS, Kubernetes, database and RDP/VNC bastion/PAM that doesn't need additional client-side software

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Squid Web Proxy Cache - Source Code

Single Packet Authorization > Port Knocking

pam_pkcs11 Bugfix