
awesome-web-hacking
Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Exploit for CVE-2024-5124 targeting ChuanhuChatGPT via TLS timing side-channel attack. Uses tlsfuzzer to perform character-by-character credential…

Disrupt WAF by abusing SSL/TLS Ciphers

Python Implementation of a .NET Padding Oracle Assessment Tool

Demonstrates a padding oracle attack against AES-CBC encryption using a vulnerable Flask decrypt endpoint and a Python exploit script to decrypt…

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

:skull: :unlock: CLI tool for PKCS7 padding oracle attacks

RememberMe Padding Oracle Vulnerability RCE

Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)

Proof-of-concept exploit that recovers the site_key for OSSN 5.3 and above, exploiting CVE-2020-10560 arbitrary file read vulnerability.

Web interface to change and reset password in an LDAP directory

This repo describes a vulnerability affecting the QR code based pairing process of the eWeLink IoT devices (CVE-2020-12702).

OWASP Thick Client Application Security Verification Standard

Simple and flexible tool for managing secrets

Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…

Check rclone config files for insecure passwords

sprint encode (plan text) get enc password

Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with…