
Vulnerability-Assessment-Exploitation-Lab
Full-lifecycle penetration test of a legacy Linux environment (Metasploitable 2) emulated on Apple Silicon. Demonstrating network reconnaissance, RCE…

Full-lifecycle penetration test of a legacy Linux environment (Metasploitable 2) emulated on Apple Silicon. Demonstrating network reconnaissance, RCE…

Responsible disclosure write-up for CVE-2025-14175 involving weak cryptographic algorithm support in the SSH server of TP-Link TL-WR820N.

Demo of CVE-2021-27568: Insecure randomness in token generation

(CVE-2023-31290) Trust Wallet Core before 3.1.1, as used in the Trust Wallet browser extension before 0.0.183, allows theft of funds because the…

investigate vulnerability of opgp-service to message signature bypass (CVE-2019-9153) of openpgp

This is the Heratbleed bug (CVE-2014-0160) documentation I did for Advenced Cyber Attacks course.

Test tool to demonstrate the vulnerability of CVE-2022-21449

Proof-of-concept for CVE-2020-13777 (GnuTLS TLS 1.3 reconnect vulnerability). Parses pcap files to demonstrate the flaw for educational and technical…

Proof-of-concept exploit demonstrating Ruby OpenSSL CA private key spoofing vulnerability (CVE-2014-2734) via public key manipulation before private…

ROCA attack on vulnerability CVE-2017-15361

Test code for poodle attack (CVE-2014-3566)

The Heartbleed bug `CVE-2014-0160` is a severe implementation flaw in the OpenSSL library, which enables attackers to steal data from the memory of…

Demos the Psychic Signatures vulnerability (CVE-2022-21449)

Demonstrates the Java Cryptography Architecture vulnerability CVE-2022-21449, showcasing the signature verification bypass with a proof-of-concept…

Educational demo of CVE-2022-21449 Java ECDSA signature bypass using real and fake JWT tokens to illustrate the vulnerability and its impact on…

Educational Python project implementing elliptic curve cryptography (ECDSA, ECIES) and simulating exploitation of CVE-2022-21449, with visualizations…

Python implementations of cryptographic attacks and utilities.

Cryptanalysis golf: break schemes and prove it in Lean 4. Proof-of-concept board.