
crapsecrets
A library for detecting known secrets across many web frameworks

A library for detecting known secrets across many web frameworks

Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

Cracking utility to bypass premium access controls on Messari's research platform, enabling unauthorized access to premium reports and real-time…

Disrupt WAF by abusing SSL/TLS Ciphers

A POC OF CVE-2022-2274 (openssl)

Simple test for the May 2016 OpenSSL padding oracle (CVE-2016-2107)

A checker (site and tool) for CVE-2014-0160

Mifare Classic Plus - Hardnested Attack Implementation for SCL3711 LibNFC USB reader

Demonstration of CVE-2020-0601 aka curveball. Based on the PoC's available at https://github.com/kudelskisecurity/chainoffools and…

Curated inventory of cybersecurity tools and resources covering penetration testing, forensics, OSINT, web security, malware analysis, cryptography,…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

PoC for CVE-2020-0601 - CryptoAPI exploit

Padding oracle exploit for Oracle Access Manager (CVE-2018-2879) enabling decryption of encrypted cookies and encryption of arbitrary plaintext for…

Proof-of-concept exploit for CVE-2014-0160 (Heartbleed) targeting DTLS, demonstrating memory disclosure vulnerability in TLS/DTLS implementations.

Hardware tool for RFID analysis, emulation, and penetration testing. Supports 125kHz, 13.56MHz protocols (MIFARE, iClass, ISO14443/15693) with key…

Manage WhatsApp .crypt12, .crypt14 and .crypt15 files.

A curated list of CTF frameworks, libraries, resources and softwares

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…