
TLS-Attacker
Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

A list of web application security

Application-layer protocol framework for trust-based, end-to-end encrypted communication across heterogeneous networks, enabling uniform service…

:skull: :unlock: CLI tool for PKCS7 padding oracle attacks

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

RememberMe Padding Oracle Vulnerability RCE

Detects Windows and Linux systems with enabled Trusted Platform Modules (TPM) vulnerable to CVE-2017-15361. #nsacyber

sprint encode (plan text) get enc password

A secure offline desktop application for generating and managing TOTP 2FA codes. Features encrypted vault storage, modern cryptography (Argon2 +…

OWASP Thick Client Application Security Verification Standard

Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…

Check rclone config files for insecure passwords

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)

Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with…
