
awesome-web-hacking
A list of web application security

A list of web application security

Application-layer protocol framework for trust-based, end-to-end encrypted communication across heterogeneous networks, enabling uniform service…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

OWASP Thick Client Application Security Verification Standard

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…


:skull: :unlock: CLI tool for PKCS7 padding oracle attacks

RememberMe Padding Oracle Vulnerability RCE

Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)


Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…

Check rclone config files for insecure passwords

sprint encode (plan text) get enc password

Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with…

Detects Windows and Linux systems with enabled Trusted Platform Modules (TPM) vulnerable to CVE-2017-15361. #nsacyber

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

This repo describes a vulnerability affecting the QR code based pairing process of the eWeLink IoT devices (CVE-2020-12702).