
433Screen-SignalHacker
Full duplex 433 MHz Signal jammer, recorder, decoder and hacking multitool device based on ESP32 microcontroller and RFM69HW radios. This version of…

Full duplex 433 MHz Signal jammer, recorder, decoder and hacking multitool device based on ESP32 microcontroller and RFM69HW radios. This version of…

IoTGoat is a deliberately insecure firmware based on OpenWrt.

BLE-based Fitbit research tool for authentication replay, encrypted activity dump decryption, memory/firmware extraction, and custom firmware…

Exploit code for CVE-2021-27246 targeting TPLink Archer routers, demonstrated at Pwn2Own 2020 Tokyo. Includes proof-of-concept for remote code…

Displays an old-school crack-intro animation on compromised Canon and Lexmark printers, with SDL2 and WebAssembly builds for portability and study.

Proof-of-concept exploit for CVE-2023-20126 targeting Cisco SPA phone adapters. Uploads malicious firmware to gain a root shell on port 23000/tcp via…

Full disk encryption for Kali on Raspberry using LUKS

A coordinated disclosure and security advisory on Fermax Intercom DTML Injection vulneraiblity. Special thanks to Fermax International for prompt…

The results of my small term paper on the topic of the Internet of Vulnerable Things and the exploit for CVE-2022-48194.

Local streaming tool for cheap WiFi cameras that bypasses cloud services and phone apps. Discovers cameras on your network, authenticates via PPPP…

Interactive wizard to flash EFF's Rayhunter on Orbic RC400L — auto-detects OS

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…

This repository holds interesting bits and pieces related to research I performed on wireless presentation devices manufactured by Awindinc and…

Exploit implementation for CVE-2023-45866 enabling unauthenticated Bluetooth keyboard injection using DuckyScript payloads on Raspberry Pi.

Proof-of-concept exploit for CVE-2025-29384, a critical stack-based buffer overflow in Tenda AC9 routers. Includes Python and Metasploit modules for…

Boots a custom Linux kernel on rooted LG webOS TVs via kexec, with reverse-engineered SoC watchdog support, framebuffer payloads, and an initramfs…

Proof-of-concept exploit for a heap buffer overflow in libpng on PS4/PS5. Generates a malicious PNG that triggers the vulnerability when opened in…

Unauthenticated Address Book Modification on Sharp MX/BP Multifunction Printers