
papers
A handy collection of my public papers, all in one place.

A handy collection of my public papers, all in one place.

Results and device code from the DEF CON 29 presentation "You're Doing IoT RNG"

Proxmark3 Lua script for attacking vulnerable Protectimus SLIM NFC TOTP hardware tokens

This repository contains a few vulnerabilities that were found and reported during vulnerability assessments.

Documents CP PLUS EZ-P21 IP camera CVEs: arbitrary code execution via debug feature and improper authentication of HTTP endpoints, with responsible…

Workshop on firmware reverse engineering

Proof-of-concept exploit for CVE-2026-1668.

Rust tool to detect cell site simulators on an orbic mobile hotspot

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

PrISM: A Scalable Probabilistic RowHammer Mitigation (ISCA 2026). Ramulator2 source code and evaluation scripts.

Full disk encryption for Kali on Raspberry using LUKS

Awesome-Cellular-Hacking

a list of BIOS/Firmware fixes adressing CVE-2017-5715, CVE-2017-5753, CVE-2017-5754


The results of my small term paper on the topic of the Internet of Vulnerable Things and the exploit for CVE-2022-48194.

A denial-of-service vulnerability in the AuntyFey BLE smart padlock allows unauthenticated connection floods to lock out legitimate users. …
