
jwt_tool
:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Proof-of-concept exploit for CVE-2024-52510 demonstrating signature bypass in Nextcloud's E2EEv2 protocol, enabling server-side decryption of…

Secure tunneling daemon implementing VPN protocols with TLS encryption, certificate authentication, and routing/firewall configuration for private…

A lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the…

Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

Proof-of-concept denial-of-service tool that exploits the DHEat attack (CVE-2002-20001) by enforcing Diffie-Hellman key exchange against TLS and SSH…

An open-source framework for verifiably private AI inference

A checker (site and tool) for CVE-2014-0160

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

Simple and flexible tool for managing secrets

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Ed25519 signed receipts + Cedar policies for AI agents. Finance mandate gate (Legate), proof packs, 3 IETF Internet-Drafts. npx protect-mcp

Testing TLS/SSL encryption anywhere on any port

Single Packet Authorization > Port Knocking

Practical labs, notes, and reports for CEH v13 modules — covering web hacking, network pentesting, malware analysis, social engineering, and security…

Agent Control Protocol (ACP) — Official English specification. Cryptographically verifiable authorization architecture for autonomous AI agents.

🔐 A CLI tool to extract server certificates

:skull: :unlock: CLI tool for PKCS7 padding oracle attacks