
sops
Simple and flexible tool for managing secrets

Simple and flexible tool for managing secrets

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Analyzes DNS delegation and DNSSEC security by probing resolvers and authoritative servers, then validating, diagnosing, and visualizing zone…

Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…

Demonstrates a padding oracle attack against AES-CBC encryption using a vulnerable Flask decrypt endpoint and a Python exploit script to decrypt…

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

OWASP Thick Client Application Security Verification Standard

Check rclone config files for insecure passwords

Kerberos RC4 deprecation: detection, remediation and guidance (CVE-2026-20833)

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

A secure offline desktop application for generating and managing TOTP 2FA codes. Features encrypted vault storage, modern cryptography (Argon2 +…

Improper Certificate Chain Validation in EagleEyes Lite Android Application

Java security framework providing authentication, authorization, cryptography, and session management APIs to secure any application from mobile to…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Exploit for CVE-2024-5124 targeting ChuanhuChatGPT via TLS timing side-channel attack. Uses tlsfuzzer to perform character-by-character credential…

Application-layer protocol framework for trust-based, end-to-end encrypted communication across heterogeneous networks, enabling uniform service…