
POC_CVE-2015-9235
Demo of the algorithm confusion attack on various JWT libraries

Demo of the algorithm confusion attack on various JWT libraries

Interactive cybersecurity scenario simulating a Tesla TPMS to VCSEC to CAN Bus attack chain, teaching vehicle security concepts through gamified…

Step-by-step walkthrough of a LetsDefend SOC342 lab analyzing CVE-2025-53770 SharePoint ToolShell auth bypass and RCE, including attack chain,…

Educational Jupyter notebook demonstrating the Dual_EC_DRBG cryptographic backdoor (CVE-2014-8610) with NIST P-256 state recovery attack, historical…

CTF challenge demonstrating CVE-2024-4577 PHP CGI argument injection, with vulnerable app, attack scripts, and Kubernetes/Docker deployment for…

CSRF vulnerability PoC and remediation guide for employee deactivation in an admin panel. Includes CVSS scoring, attack reproduction steps, and…

Offline-first dashboard for tracking CTF machines and labs, with attack lifecycle management, dynamic reverse shell builder, and embedded writeup…

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

A collection of useful links for Pentesters

Configure your Pi Zero 2W to be a BadUSB

Educational Docker-based lab demonstrating the Heartbleed bug (CVE-2014-0160) with hacker, victim, and server containers for hands-on exploitation…

[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…

Automated Adversary Emulation Platform

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash

Hands-on AI security lab platform with 50+ scenarios across prompt injection, agentic system exploitation, model manipulation, and MCP trust boundary…

Evaluation framework that tests whether large language models follow invisible Unicode-encoded instructions embedded in normal-looking text, with…

CMS Made Simple < 2.2.10 - SQL Injection . Actual working version