
BlueSpy
PoC to record audio from a Bluetooth device

PoC to record audio from a Bluetooth device

UPnP Pentest Toolkit for Windows

AirPods liberated from Apple's ecosystem.

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

PIrateRF transforms your Raspberry Pi Zero W into a portable RF signal generator that spawns its own WiFi hotspot. Control everything from FM…

My first Android app: Launch Fusée Gelée payloads from stock Android (CVE-2018-6242)

Hardened Android web browser forked from Mull/Firefox with privacy-focused patches, anti-fingerprinting, telemetry removal, and secure defaults for…

Telenet Enable for Netgear routers from svn checkout http://netgear-telnetenable.googlecode.com/svn/trunk/ netgear-telnetenable-read-only

Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…

Results and device code from the DEF CON 29 presentation "You're Doing IoT RNG"

Critical vulnerability in Siemens RuggedCom ROS devices allowing attackers to derive a hidden factory account password from the device MAC address…

CAWODOG is a proof-of-concept project demonstrating how to protect Python-based AI models deployed on offline industrial machines. Across three…

This is a collection of Unisoc BootROMs i've dumped from various Unisoc chipsets via CVE-2022-38694

Proof of Concept of ESP32/8266 Wi-Fi vulnerabilties (CVE-2019-12586, CVE-2019-12587, CVE-2019-12588)

Proof of Concept of Sweyntooth Bluetooth Low Energy (BLE) vulnerabilities.


CAN bus injection toolkit for automotive security testing. Performs interface control, sniffing, and CAN injection attacks on vehicle networks,…