
keeper
Simple Secure Keeper for Secrets

Simple Secure Keeper for Secrets

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

JSON Web Token (JWT) encoding and decoding for Kit

JWT Attack to change the algorithm RS256 to HS256

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…

Python POC, Exploit for CVE-2026-29000

Centralizes identity, authentication, and access control for Linux/UNIX environments using LDAP, Kerberos, PKI, DNS, and Active Directory trust.

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Secure tunneling daemon implementing VPN protocols with TLS encryption, certificate authentication, and routing/firewall configuration for private…

A lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the…

The leading native Python SSHv2 protocol library.

Transparent file encryption in git

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

Certificate authority issuing short-lived code-signing certificates tied to OpenID Connect identities, enabling verifiable software supply chain…

Implementation of Kerberos, PKI, and ASN.1/DER providing authentication, authorization, and cryptographic services for secure networks.

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

Secure terminal chat. E2E encrypted, zero-metadata blind-forwarder server. PyNaCl XSalsa20-Poly1305 + Ed25519 + forward secrecy. Cross-platform…