
pentest-guide
Penetration tests guide based on OWASP including test cases, resources and examples.

Penetration tests guide based on OWASP including test cases, resources and examples.

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

Testing TLS/SSL encryption anywhere on any port

A list of web application security

Fast SSL/TLS scanner that discovers supported cipher suites, protocols, and vulnerabilities (Heartbleed, POODLE, CRIME) with certificate chain…

A checker (site and tool) for CVE-2014-0160


Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll)

A library for detecting known secrets across many web frameworks

Automated script for performing Padding Oracle attacks

Paranoid's library contains implementations of checks for well known weaknesses on cryptographic artifacts.

ROCA: Infineon RSA key vulnerability

One day based on https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html

O-Saft - OWASP SSL advanced forensic tool

A PoC for CVE-2020-0601

Heartbleed (CVE-2014-0160) client exploit

Automated TLS server and client configuration scanner for pentesters and researchers. Evaluates cipher suites, protocol versions, and security…