
testssl.sh
Testing TLS/SSL encryption anywhere on any port

Testing TLS/SSL encryption anywhere on any port

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

Audits SSH servers for weak Diffie-Hellman key exchange groups by testing multiple client configurations, identifying Logjam-vulnerable endpoints…

Go-based MITM exploit demo for OpenSSL CVE-2014-0224 (CCS Injection) targeting RC4-SHA cipher, with server/client proxy setup for testing TLS…

Proof-of-concept denial-of-service tool that enforces Diffie-Hellman ephemeral key exchange over TLS and SSH to saturate server CPU, implementing…

Red Team Coin for crypto-mining operations.

A library for detecting known secrets across many web frameworks

SAML2 Burp Extension

notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)

A checker (site and tool) for CVE-2014-0160

A little toolbox to play with Microsoft Kerberos in C

O-Saft - OWASP SSL advanced forensic tool

A library for detecting known secrets across many web frameworks

Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

Automated TLS server and client configuration scanner for pentesters and researchers. Evaluates cipher suites, protocol versions, and security…

Mifare Classic Plus - Hardnested Attack Implementation for SCL3711 LibNFC USB reader

One day based on https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html

Heartbleed (CVE-2014-0160) client exploit