
awesome-web-hacking
Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Application-layer protocol framework for trust-based, end-to-end encrypted communication across heterogeneous networks, enabling uniform service…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

OWASP Thick Client Application Security Verification Standard

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

Exploit for CVE-2024-5124 targeting ChuanhuChatGPT via TLS timing side-channel attack. Uses tlsfuzzer to perform character-by-character credential…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Demonstrates a padding oracle attack against AES-CBC encryption using a vulnerable Flask decrypt endpoint and a Python exploit script to decrypt…

:skull: :unlock: CLI tool for PKCS7 padding oracle attacks

RememberMe Padding Oracle Vulnerability RCE

Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)

Proof-of-concept exploit that recovers the site_key for OSSN 5.3 and above, exploiting CVE-2020-10560 arbitrary file read vulnerability.

Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…

Analyzes DNS delegation and DNSSEC security by probing resolvers and authoritative servers, then validating, diagnosing, and visualizing zone…

Simple and flexible tool for managing secrets

Check rclone config files for insecure passwords

Perl scripts for SSL/TLS analysis: check protocol and cipher support, verify certificates, test OCSP, and detect Heartbleed across SMTP, HTTPS, and…

sprint encode (plan text) get enc password