


A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics,…

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

SAML2 Burp Extension

PoC and writeup for CVE-2026-46395: unauthenticated private key disclosure via broken HMAC in HAXcms Node.js (CWE-321/CWE-200). Authorized security…

SAML2 Burp Extension

CVE-2022-35513 | blink1-pass-decrypt

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

:skull: :unlock: CLI tool for PKCS7 padding oracle attacks

Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler.

RememberMe Padding Oracle Vulnerability RCE

Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)

Exploit for Oracle Access Manager padding oracle vulnerability (CVE-2018-2879)

PoC for CVE-2025-65945 (Improper Verification of Cryptographic Signature in node-jws)

Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish…

Python POC, Exploit for CVE-2026-29000
