
Flask-Unsign
Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Walkthroughs for Capture the Flag challenges on the HTB Cybersecurity Platform.

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Discover hidden debugging parameters and uncover web application secrets

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.