
messari-crack
Cracking utility to bypass premium access controls on Messari's research platform, enabling unauthorized access to premium reports and real-time…

Cracking utility to bypass premium access controls on Messari's research platform, enabling unauthorized access to premium reports and real-time…

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

AES-CFB IV Generation Vulnerability in Reolink Desktop Application

Proof-of-concept exploit for CVE-2024-53522, demonstrating decryption of HOSxP XE database credentials using a static hard-coded private key-IV.

Proof-of-concept exploit for CVE-2026-26012, a broken access control in Vaultwarden that allows any organization member to enumerate and decrypt all…

Cryptanalysis golf: break schemes and prove it in Lean 4. Proof-of-concept board.

Python implementations of cryptographic attacks and utilities.

Repository to index useful tools for CTF's

Curated CTF writeup collection for GlacierCTF 2023 covering pwn, rev, web, crypto, and smart contract challenges with solutions and educational…

Educational study of Bitcoin key entropy: weak-RNG wallet enumeration (Milk Sad / CVE-2023-39910 class) vs. the infeasibility of brute-forcing a good…

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

Files + Writeups for DownUnderCTF 2022 Challenges

Demonstrates AES-GCM nonce-reuse exploitation by collecting same-nonce ciphertexts, leading to GHASH key leakage, message forgery, and key recovery…

Demonstrates a padding oracle attack against AES-CBC encryption using a vulnerable Flask decrypt endpoint and a Python exploit script to decrypt…

Software-only proof of concept for CVE-2025-52464 in Meshtastic Direct Messages

Technical analysis and PoC of CVE-2026-52824: default APP_SECRET in the Kimai Docker image enabling unauthenticated login link forgery. Affects <=…

Educational Python simulation demonstrating ECDSA nonce reuse in IoT firmware signing, showing how an attacker can recover private keys from two…

Known attacks on Elliptic Curve Cryptography