
CVE-2025-15467
Working DoS for CVE-2025-15467 and a docker container to test against

Working DoS for CVE-2025-15467 and a docker container to test against

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

Demonstration of Go's dsa.Verify bug (CVE-2019-17596)

Client-side PKI toolbox that decodes X.509, CSR, chain, CRL, PKCS#7 and PKCS#12 artifacts, views ASN.1, converts formats, and generates self-signed…

Disabled TLS Certificate Verification for HashiCorp Vault KMS in confluent-kafka

CVE-2019-5010 Exploit PoC - Python Denial of Service via Malformed X.509v3 Extension

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)

Remove visible and invisible AI watermarks and provenance metadata from images and video. Python library and CLI for SynthID, C2PA, EXIF, IPTC, XMP,…

Audits SSH servers for weak Diffie-Hellman key exchange groups by testing multiple client configurations, identifying Logjam-vulnerable endpoints…

Proof-of-concept exploit for CVE-2022-0778, a denial-of-service vulnerability in OpenSSL's BN_mod_sqrt() function, with Docker-based lab environment…

CVE-2025-14847 explaination and lab

My manifesto, and stories, images, and phun stuff

Finding CVE-2022-3786 (openssl) with Mayhem

Pure PQC two-tier PKI hierarchy using ML-DSA-65 (NIST FIPS 204) on EJBCA Community Edition — Root CA + Sub CA with CRL and OCSP

POC for CVE-2025-24132 (AirBourne). Currently just triggers the overflow and causes a crash

Challenge handouts, source code, and solutions for UofTCTF 2025

C library implementing FrodoKEM, a post-quantum key encapsulation mechanism based on the Learning with Errors problem, with variants for AES and…