
AspDotNetWrapper-Edited-
Decrypts ASP.NET ViewState payloads using candidate machine keys, letting security testers validate weak or exposed machineKey configurations in web…

Decrypts ASP.NET ViewState payloads using candidate machine keys, letting security testers validate weak or exposed machineKey configurations in web…

Portable Python API for exploiting padding oracle vulnerabilities with pluggable oracle() handlers, block-size and IV support, and decryption of…

CodeIgniter <=2.1.4 session cookie decryption vulnerability

Burp Suite extension enhancing Collaborator with context capture, polling history, and optional AES-encrypted authentication for private server…

Python Implementation of a .NET Padding Oracle Assessment Tool

Burp Suite extension for interactive data extraction and transformation in HTTP traffic with configurable node tree supporting Base64, JSON, XML, URL…

Скрипт для расшифровки пароля пользователя в СЭД Detrix

A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications.

Decrypt and re-encrypt Laravel session cookies to exploit insecure PHP deserialization for remote code execution.

Java-based exploit tool for reading and decrypting database configuration files from vulnerable Fanwei OA instances by accessing a specific JSP…

Rust-based brute-force scanner for Laravel APP_KEYs: inlines AES-NI decryption, supports single and batch key testing against encrypted ciphertexts.

Decrypts AES-encrypted web requests and integrates with Intruder for automated brute-force cracking of login credentials via custom payload processor.

Proof-of-concept exploit demonstrating JWT/JWE authentication bypass by forging unverified tokens with alg:none, wrapped in valid JWE encryption…

Python-based tool to verify CVE-2016-4437 by decoding Apache Shiro rememberMe cookies, extracting CBC encryption IV offsets, and detecting vulnerable…

Burp Suite extension for testing SAML infrastructures. Manipulate SAML messages, perform signature spoofing, XSW, XXE, and XSLT attacks, and manage…

PHP-based remote administration tool with encrypted C2 communication, built-in agent generator, and proxy support for post-exploitation after web…

Exploit for Apache RocketMQ CVE-2019-17572 targeting distributed messaging platforms with authentication and encryption features.

Automated exploitation toolkit for Hikvision IP cameras. Performs snapshot access, config decryption, credential extraction, and remote command…