

Fuzzes CPU implementations by generating test inputs from software proxies, then executes them on real hardware to detect microarchitecture defects…

Curated collection of offensive security conference slide decks covering kernel and mobile exploitation, VM/container escapes, and…

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

UT based automated fuzz driver generation

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

exploits and proof-of-concept vulnerability demonstration files from the team at Hacker House

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

Proof of Concept of Sweyntooth Bluetooth Low Energy (BLE) vulnerabilities.

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

One IPv6 ND option with length zero. One missing check. Daemon walks backward and lives in the loop. Reported to OpenBSD, fixed, CVE assigned.

A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)



PoC for Foxit Reader CVE-2018-14442

针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)