
p5-ssl-tools
Perl scripts for SSL/TLS analysis: check protocol and cipher support, verify certificates, test OCSP, and detect Heartbleed across SMTP, HTTPS, and…

Perl scripts for SSL/TLS analysis: check protocol and cipher support, verify certificates, test OCSP, and detect Heartbleed across SMTP, HTTPS, and…

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

Kerberos RC4 deprecation: detection, remediation and guidance (CVE-2026-20833)

Analyzes DNS delegation and DNSSEC security by probing resolvers and authoritative servers, then validating, diagnosing, and visualizing zone…

Demonstrates a padding oracle attack against AES-CBC encryption using a vulnerable Flask decrypt endpoint and a Python exploit script to decrypt…

RememberMe Padding Oracle Vulnerability RCE

Python Implementation of a .NET Padding Oracle Assessment Tool

sprint encode (plan text) get enc password

Web interface to change and reset password in an LDAP directory

Check rclone config files for insecure passwords

OWASP Thick Client Application Security Verification Standard

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)

Java security framework providing authentication, authorization, cryptography, and session management APIs to secure any application from mobile to…

This repo describes a vulnerability affecting the QR code based pairing process of the eWeLink IoT devices (CVE-2020-12702).

Improper Certificate Chain Validation in EagleEyes Lite Android Application

Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.