
MemorizingTrustManager
A "plugin" for Android Java to allow asking the user about SSL certificates

A "plugin" for Android Java to allow asking the user about SSL certificates

Kankun Smart Socket Hijacker and Sniffer. The kankun smart socket and its mobile app use a hardcoded AES 256 bit key to encrypt and decrypt…

Python utility to check if Android verified boot images (vbmeta) are signed with publicly known test keys, identifying misconfigurations in release…

Pixnapping Attack: Compromising private keys and seed phrases through vulnerability CVE-2025-48561 represents a new critical threat to the Bitcoin…

Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14…

eWeLinkESPT is a tool that automatically decodes and decrypts the WiFi network credentials transmitted to a supported ESP-based IoT device by the…

This repo describes a vulnerability affecting the QR code based pairing process of the eWeLink IoT devices (CVE-2020-12702).

A modern, portable, easy to use crypto library.

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so…

Home to the Signal Protocol as well as other cryptographic primitives which make Signal possible.

The wolfSSL library is a small, fast, portable implementation of TLS/SSL for embedded devices to the cloud. wolfSSL supports up to TLS 1.3 and DTLS…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

C-based library for parsing, editing, and saving EXIF metadata from JPEG images, with a focus on exploiting CVE-2016-6328 for Android 10.

ZTE SmartLife security findings leading to account takeover: 100K+ Google Play downloads and CVE-2026-86552 through CVE-2026-86555.

User-friendly Lightweight TPM Remote Attestation over Bluetooth

Zip file format fuzzer and multi-tool.

Proof-of-concept exploit for CVE-2016-6271 demonstrating ZRTP man-in-the-middle attack via hash-commitment bypass in libbzrtp, with Docker-based…