
HomePWN
HomePwn - Swiss Army Knife for Pentesting of IoT Devices

HomePwn - Swiss Army Knife for Pentesting of IoT Devices

Crack and decrypt BLE encryption

Bluetooth experimentation framework for Broadcom and Cypress chips.

Mousejack for ATmega32u4

80+ feature pentesting firmware for M5Stack Cardputer-Adv. WiFi, BLE, sub-GHz (CC1101), 2.4GHz (nRF24), LoRa (SX1262), IR, BadUSB, DHCP attacks,…

Hijacking Bluetooth Accessories Using Google Fast Pair: WhisperPair CVE-2025-36911 Reference Implementation & Vulnerability Verification Toolkit


Curated guide to IoT penetration testing hardware and software tools for 2025, covering Bluetooth, Zigbee, Z-Wave, WiFi, RFID, automotive, and…

Linux Bluetooth - Run arbitrary management commands as an unprivileged user

BLE-based Fitbit research tool for authentication replay, encrypted activity dump decryption, memory/firmware extraction, and custom firmware…

CVE-2017-0785 BlueBorne PoC

Scan/Exploit Blueborne CVE-2017-0785

Python-Based Pentesting Framework

PoC vulnerability disclosures for consumer IoT cameras, detailing BLE buffer overflow and WiFi disassociation attacks that can take devices offline.

RF CHAOS is an Android App That Is Designed To Cause Chaos via All RF Adapters Possible - Enjoy!

Reverse-engineered Logi Options+ agent IPC protocol. Switch Logitech multi-host devices programmatically via Unix socket (macOS) or named pipe…

CVE-2024-21306 BadBlue implementation (Using DuckyScript)

PoC for 2023-52709 - TI Bluetooth stack can fail to generate a resolvable Random Private Address (RPA) leading to DoS for already bonded peer devices.