
CVE-2024-5764
Python script to decrypt data encrypted by the Java PasswordCipher class, exploiting CVE-2024-5764's static encryption key in Sonatype Nexus…

Python script to decrypt data encrypted by the Java PasswordCipher class, exploiting CVE-2024-5764's static encryption key in Sonatype Nexus…

Decrypts weak encrypted passwords from Argus Surveillance DVR systems via CVE-2022-25012, reconstructing plaintext credentials from DVRParams.ini…

Voron messenger crypto/protocol library (X3DH-lite + Double Ratchet, group sender-keys, onion transport) — external review requested

CVE-2022-35513 | blink1-pass-decrypt

Python toolkit for decrypting AES-256 and cracking PBKDF2 passwords from Grafana databases usually paired with (CVE-2021-43798)

Exploitation toolkit for CVE-2025-59287 RCE in WSUS. Includes AES payload encryption and an exploitation module for authorized penetration testing.

Weak encryption in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject wireless…

CVE-2022-27499

Multiplatform steganography app with GUI, CLI and WebService, supports WEBP and AES.

Detailed technical write-up and proof-of-concept for CVE-2022-26923, an Active Directory Certificate Services privilege escalation vulnerability,…

Resources and PoCs

Comprehensive Java utility library providing modules for cryptography, HTTP client, caching, JSON, scripting, and captcha generation, simplifying…

Portable zipfile extraction utility with broad OS support, decryption, and security fixes for path traversal and symlink vulnerabilities.

Extracts and decrypts inner payloads from Donut obfuscator samples by detecting loader shellcode signatures, parsing the DONUT_INSTANCE structure,…

The next level 100% Python obfuscator.

A listener profile for the Mythic C2 framework that utilizes AI vendors file API's

Information Protection & OSINT resources | 一个关于数字隐私搜集、保护、清理集一体的方案,外加开源信息收集(OSINT)对抗