
CMF-Watch-Pro-2-BLE-Protocol
Reverse-engineered BLE protocol for the CMF Watch Pro 2, documenting GATT layout, AES-128-CBC encrypted command frames, authentication handshake, and…

Reverse-engineered BLE protocol for the CMF Watch Pro 2, documenting GATT layout, AES-128-CBC encrypted command frames, authentication handshake, and…

An app with really insecure crypto. To be used to see/test/exploit weak cryptographic implementations as well as to learn a little bit more about…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Proof of concept demonstrating insecure AES-CBC encryption with MD5 key derivation in the Meesho Android app, enabling ciphertext tampering and…

The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Offline, open-source web app for passkey-based file encryption and sharing. AES-256-GCM/HPKE, no cloud, no accounts; encrypt to recipients with…

Vault app for DC34 badge

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

PoC repository for CVE-2020-6861: Ledger Monero App Spend key Extraction

Kankun Smart Socket Hijacker and Sniffer. The kankun smart socket and its mobile app use a hardcoded AES 256 bit key to encrypt and decrypt…

Multiplatform steganography app with GUI, CLI and WebService, supports WEBP and AES.

Open-source iOS messenger providing end-to-end encrypted text, voice, and video calls via the Signal Protocol, with no analytics or telemetry…

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Exploit for Oracle Access Manager padding oracle vulnerability (CVE-2018-2879)

Nounours is a tool designed to test APP_KEYs at scale on Laravel applications.

Manage WhatsApp .crypt12, .crypt14 and .crypt15 files.