
CVE-2024-53522
Proof-of-concept exploit for CVE-2024-53522, demonstrating decryption of HOSxP XE database credentials using a static hard-coded private key-IV.

Proof-of-concept exploit for CVE-2024-53522, demonstrating decryption of HOSxP XE database credentials using a static hard-coded private key-IV.

Proof-of-concept exploit for CVE-2026-26012, a broken access control in Vaultwarden that allows any organization member to enumerate and decrypt all…

Cryptanalysis golf: break schemes and prove it in Lean 4. Proof-of-concept board.

Python implementations of cryptographic attacks and utilities.

Repository to index useful tools for CTF's

Curated CTF writeup collection for GlacierCTF 2023 covering pwn, rev, web, crypto, and smart contract challenges with solutions and educational…

Educational study of Bitcoin key entropy: weak-RNG wallet enumeration (Milk Sad / CVE-2023-39910 class) vs. the infeasibility of brute-forcing a good…

Home to the Signal Protocol as well as other cryptographic primitives which make Signal possible.

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

Files + Writeups for DownUnderCTF 2022 Challenges

Demonstrates AES-GCM nonce-reuse exploitation by collecting same-nonce ciphertexts, leading to GHASH key leakage, message forgery, and key recovery…

Demonstrates a padding oracle attack against AES-CBC encryption using a vulnerable Flask decrypt endpoint and a Python exploit script to decrypt…

Software-only proof of concept for CVE-2025-52464 in Meshtastic Direct Messages

A webshell and a normal file that have the same MD5

Technical analysis and PoC of CVE-2026-52824: default APP_SECRET in the Kimai Docker image enabling unauthenticated login link forgery. Affects <=…

Educational Python simulation demonstrating ECDSA nonce reuse in IoT firmware signing, showing how an attacker can recover private keys from two…

Known attacks on Elliptic Curve Cryptography