
proxmark3
Hardware tool for RFID analysis, emulation, and penetration testing. Supports 125kHz, 13.56MHz protocols (MIFARE, iClass, ISO14443/15693) with key…

Hardware tool for RFID analysis, emulation, and penetration testing. Supports 125kHz, 13.56MHz protocols (MIFARE, iClass, ISO14443/15693) with key…

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

Automatically find and execute fault injection attacks

EMBA - The firmware security analyzer

Python proof-of-concept for unauthenticated OS command injection in TOTOLINK N600R, exploiting the langType parameter to execute arbitrary commands…

Advisory and technical analysis of CVE-2026-15469, a hard-coded RSA-512 mesh group private key in TP-Link Deco routers, including root cause, impact,…

Reverse-engineered Logi Options+ agent IPC protocol. Switch Logitech multi-host devices programmatically via Unix socket (macOS) or named pipe…

Unlock the bootloader of any exploitable device vulnerable to CVE-2021-30327

TP-Link Archer BE800 V1 — Parental Control LAN RCE


Owning a tablet Amazon kept shutting down — CVE-2022-38181 write-up, four AI models, and a blog

FPGA-based hardware emulation platform main binary and documentation for retro system development, firmware compilation, and hardware security…

Chase H.Q. for ZX Spectrum — reverse-engineered and reconstructed in portable C

Open-source silicon RTL and simulation tools for the Baochip 1x SoC, featuring a VexRiscv CPU, Verilator-based verification, and documentation for…

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

Open-source hardware security toolchain for power trace capture, side-channel analysis, and glitching/fault-injection attacks on embedded devices and…

Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables SELinux, spawns root shell

Run Radmin VPN on Linux via Wine — custom driver, TAP bridge, zero packet loss