
Loracrack
LoRaWAN session cracker - A PoC for exploiting weak or shared Application Keys

LoRaWAN session cracker - A PoC for exploiting weak or shared Application Keys

Decrypts passwords stored in SOS JobScheduler (S)FTP profiles by exploiting the use of the profile name as the 3DES encryption key, enabling recovery…

A library for detecting known secrets across many web frameworks

Phoenix Rowhammer Attack: Systemic Risk of Bitcoin Wallet Private Key Compromise in Global Blockchain Infrastructure Due to a Critical SK Hynix DDR5…

Proof-of-concept exploit for CVE-2024-53522, demonstrating decryption of HOSxP XE database credentials using a static hard-coded private key-IV.

Analyzes DNS delegation and DNSSEC security by probing resolvers and authoritative servers, then validating, diagnosing, and visualizing zone…

Offline nested attack tool that recovers MIFARE Classic authentication keys using known default or user-supplied keys for assessing NFC/RFID card…

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

Centralizes identity, authentication, and access control for Linux/UNIX environments using LDAP, Kerberos, PKI, DNS, and Active Directory trust.

Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

secure vault for your files

Home to the Signal Protocol as well as other cryptographic primitives which make Signal possible.

bad stuffs by bad guys

Local-first encrypted password vault for Android with Master Password access, Recovery Key support, Autofill integration, and portable encrypted…

Decrypts Covenant C2 communications by extracting RSA private keys from minidumps, recovering AES session keys, and converting network captures to…

Demonstrates AES-GCM nonce-reuse exploitation by collecting same-nonce ciphertexts, leading to GHASH key leakage, message forgery, and key recovery…

Demonstrates a critical SPHINCS+ WOTS+ signature forgery caused by weak randomness and nonce reuse, recovering secrets from two (r,s) signature pairs.

Embed a payload inside a PNG file