
TLS-Attacker
Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Simple and flexible tool for managing secrets

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Web interface to change and reset password in an LDAP directory

Analyzes DNS delegation and DNSSEC security by probing resolvers and authoritative servers, then validating, diagnosing, and visualizing zone…

Application-layer protocol framework for trust-based, end-to-end encrypted communication across heterogeneous networks, enabling uniform service…

:skull: :unlock: CLI tool for PKCS7 padding oracle attacks

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

RememberMe Padding Oracle Vulnerability RCE

Detects Windows and Linux systems with enabled Trusted Platform Modules (TPM) vulnerable to CVE-2017-15361. #nsacyber

Disrupt WAF by abusing SSL/TLS Ciphers

sprint encode (plan text) get enc password

Python Implementation of a .NET Padding Oracle Assessment Tool

OWASP Thick Client Application Security Verification Standard

A secure offline desktop application for generating and managing TOTP 2FA codes. Features encrypted vault storage, modern cryptography (Argon2 +…

Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…