
Android-Security-Masterclass
OWASP hands-on Android security training lab with 78 MASVS/MASTG modules pairing vulnerable, secure, and attacker apps to demonstrate mobile…

OWASP hands-on Android security training lab with 78 MASVS/MASTG modules pairing vulnerable, secure, and attacker apps to demonstrate mobile…

Tool to find common vulnerabilities in cryptographic public keys

Proof-of-concept exploit for CVE-2022-0778, a denial-of-service vulnerability in OpenSSL's BN_mod_sqrt() function, with Docker-based lab environment…

Educational laboratory for studying CVE-2014-0160 (Heartbleed) and framing inconsistencies in TLS heartbeat handling.

Proof-of-concept exploit for CVE-2026-13447, a critical authentication bypass in the WordPress MStore API plugin via forged Firebase JWT tokens, with…

Disclosure pack and Python PoC for CVE-2026-5430, a JWT algorithm-confusion flaw in WSO2 API Manager 4.5.0 enabling unauthenticated admin account…

Automated script for performing Padding Oracle attacks

Multi-threaded Padding Oracle attacks against any service. Written in Rust.

Provides library functionality for FIDO2, including communication with a device over USB or NFC.

Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

Blazing fast, advanced Padding Oracle exploit

Application-layer protocol framework for trust-based, end-to-end encrypted communication across heterogeneous networks, enabling uniform service…

Proof of Concept for CVE-2020-0601

CVE-2022-21449 Proof of Concept demonstrating its usage with a client running on a vulnerable Java version and a malicious TLS server

JWT Attack to change the algorithm RS256 to HS256

Proof-of-concept for CVE-2021-34558, demonstrating a TLS handshake panic in Go's crypto/tls via a malicious server with mismatched certificate and…

php_mt_seed is a PHP mt_rand() seed cracker

Docker container implementing tests for CVE-2016-2107 - LuckyNegative20