
Principal-HackTheBox
Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

Demonstrates AES-GCM nonce-reuse exploitation by collecting same-nonce ciphertexts, leading to GHASH key leakage, message forgery, and key recovery…

Demonstrates a padding oracle attack against AES-CBC encryption using a vulnerable Flask decrypt endpoint and a Python exploit script to decrypt…

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…

Demonstrates a timing side-channel in Kyber KEM decapsulation using a vulnerable C server and Python attack script, measuring ciphertext rejection…

Python Implementation of a .NET Padding Oracle Assessment Tool

Minimal proof-of-concept reproducer for CVE-2025-69419, a heap buffer overflow in OpenSSL's PKCS12_get_friendlyname() triggered by a crafted…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Go package that checks if RSA keys are vulnerable to ROCA / CVE-2017-15361

Demonstrating that SSLVerifySignedServerKeyExchange() is trivially testable.

Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics,…

Simple PowerShell script to check whether a computer is using an Infineon TPM chip that is vulnerable to CVE-2017-15361.

Educational laboratory for studying CVE-2014-0160 (Heartbleed) and framing inconsistencies in TLS heartbeat handling.

Proof-of-concept exploit for CVE-2024-22894, demonstrating 3DES-encrypted root password extraction from Alpha Innotec/Novelan heatpump firmware,…

CVE-2022-21449 Proof of Concept demonstrating its usage with a client running on a vulnerable Java version and a malicious TLS server

POC exploit of CVE-2021-3345, a vulnerability in libgcrypt version 1.9.0

A generative test that would've caught CVE-2020-28052