
Flask-Unsign
Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash…

CTF wargame platform featuring Unicode bypass exploitation (CVE-2015-9238), flag file segmentation, brute force delay, and password hashing for…

Steganography brute-force utility to uncover hidden data inside files

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash


:zap: Worlds fastest steghide cracker, chewing through millions of passwords per second :zap:

Fast Steganography bruteforce tool written in Rust useful for CTF's

CMS Made Simple < 2.2.10 - SQL Injection . Actual working version

A detailed walkthrough of Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig

A collection of various awesome lists for hackers, pentesters and security researchers

Curated collection of cybersecurity resources, labs, and training materials covering ethical hacking, penetration testing, exploit development,…

A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

A collection of awesome penetration testing resources, tools and other shiny things

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis