
ubertooth
BLE sniffer and Bluetooth experimentation platform with open hardware, firmware, and limited Classic BR packet capture for wireless security work.

BLE sniffer and Bluetooth experimentation platform with open hardware, firmware, and limited Classic BR packet capture for wireless security work.

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…

BLE-based Fitbit research tool for authentication replay, encrypted activity dump decryption, memory/firmware extraction, and custom firmware…

PoC for CVE-2026-67822 stack overflow in Tenda W6-S /goform/wifiSSIDset: DoS reproducer, QEMU MIPS shim, and conceptual RCE payload skeleton.

Bluetooth keystroke injection exploit PoCs for CVE-2023-45866, CVE-2024-21306, and CVE-2024-0230 targeting Android, Linux, macOS, and iOS via…

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

Kankun Smart Socket Hijacker and Sniffer. The kankun smart socket and its mobile app use a hardcoded AES 256 bit key to encrypt and decrypt…

MOC3ingbird Exploit for Live2D (CVE-2023-27566)

Mousejack for Arduino UNO

Telenet Enable for Netgear routers from svn checkout http://netgear-telnetenable.googlecode.com/svn/trunk/ netgear-telnetenable-read-only

Ghidra processor description module for NEC/Renesas v810 and v830 families

Collection of "modchip" designs for launching payloads via the Tegra RCM bug (CVE-2018-6242)

CVE-2014-10069