
OWASP-WSTG-Rag
OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Curated directory of hacking tutorials, tools, and resources covering penetration testing, reverse engineering, web security, network analysis,…

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Automated script for performing Padding Oracle attacks

Multi-threaded Padding Oracle attacks against any service. Written in Rust.

Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

Blazing fast, advanced Padding Oracle exploit

CVE-2022-21449 Proof of Concept demonstrating its usage with a client running on a vulnerable Java version and a malicious TLS server

Application-layer protocol framework for trust-based, end-to-end encrypted communication across heterogeneous networks, enabling uniform service…

Proof-of-concept exploit for CVE-2020-0601 that generates malicious intermediate CA certificates to spoof TLS and Authenticode signatures on…

JWT Attack to change the algorithm RS256 to HS256

Proof-of-concept for CVE-2021-34558, demonstrating a TLS handshake panic in Go's crypto/tls via a malicious server with mismatched certificate and…

Cracks PHP mt_rand() seeds using optimized algorithms to recover seed from observed outputs, supporting multiple PHP versions and SIMD acceleration.

Docker container implementing tests for CVE-2016-2107 - LuckyNegative20

A script to exploit a vulnerability in xmlsec1 where xmlsec ignores loaded public keys

Vibe coded POC of exploitation of the POODLE CVE-2014-3566

Proof-of-concept exploit for CVE-2025-54887, demonstrating brute-force of authentication tags in ruby-jwe (<=1.1.0) to compromise JWE confidentiality…