
testssl.sh
Testing TLS/SSL encryption anywhere on any port

Testing TLS/SSL encryption anywhere on any port

Cracking utility to bypass premium access controls on Messari's research platform, enabling unauthorized access to premium reports and real-time…

Proof-of-concept denial-of-service tool that enforces Diffie-Hellman ephemeral key exchange over TLS and SSH to saturate server CPU, implementing…

Automated TLS server and client configuration scanner for pentesters and researchers. Evaluates cipher suites, protocol versions, and security…

O-Saft - OWASP SSL advanced forensic tool

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

A library for detecting known secrets across many web frameworks

Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish…

Vibe coded POC of exploitation of the POODLE CVE-2014-3566

Proof of Concept for CVE-2020-0601

Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler.

Audits SSH servers for weak Diffie-Hellman key exchange groups by testing multiple client configurations, identifying Logjam-vulnerable endpoints…

CVE-2022-21449 Proof of Concept demonstrating its usage with a client running on a vulnerable Java version and a malicious TLS server

A script to exploit a vulnerability in xmlsec1 where xmlsec ignores loaded public keys

CVE-2025-14611 CentreStack and Triofox full Poc/Exploit

The PQC Network Scanner is a quantum‑focused network assessment tool that scans TLS/SSL certificates across enterprise environments to identify…

PoC for CVE-2025-65945 (Improper Verification of Cryptographic Signature in node-jws)