
sops
Simple and flexible tool for managing secrets

Simple and flexible tool for managing secrets

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…

Web interface to change and reset password in an LDAP directory

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Demonstrates a padding oracle attack against AES-CBC encryption using a vulnerable Flask decrypt endpoint and a Python exploit script to decrypt…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

Terminal-based encrypted messenger with post-quantum cryptography, Double Ratchet protocol, and Tor anonymity. Features duress passphrase, deniable…

OWASP Thick Client Application Security Verification Standard

Check rclone config files for insecure passwords

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

Kerberos RC4 deprecation: detection, remediation and guidance (CVE-2026-20833)

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

A secure offline desktop application for generating and managing TOTP 2FA codes. Features encrypted vault storage, modern cryptography (Argon2 +…

Improper Certificate Chain Validation in EagleEyes Lite Android Application

Java security framework providing authentication, authorization, cryptography, and session management APIs to secure any application from mobile to…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…