
You-re-Doing-IoT-RNG
Results and device code from the DEF CON 29 presentation "You're Doing IoT RNG"

Results and device code from the DEF CON 29 presentation "You're Doing IoT RNG"

Proof-of-concept demonstrating a firmware signature verification bypass in Phison S11 SSDs, allowing attackers to re-sign modified firmware by…

Reproduction of the Retbleed (CVE-2022-29900/29901) micro-architectural attack in gem5. RSB underflow, Flush+Reload side-channel leak, and a verified…

Demonstrates CVE-2022-34303 Secure Boot bypass via CryptoPro signed UEFI Shell, using the mm command to nullify gSecurity2 and load unsigned UEFI…

This is a hypothetical demonstration of the process involved in exploiting LogoFail, it theoretically includes the necessary steps.

Unauthenticated RCE exploit for Fantec MWiD25-DS

Demonstrates CVE-2022-34301 Secure Boot bypass via Eurosoft signed UEFI Shell (esdiags.efi), using the mm command to nullify gSecurity2 and load…

Public version of the Entropica repo

Comprehensive reverse engineering and exploitation of CVE-2019-17147, a stack buffer overflow in TP-Link TL-WR841N routers. Includes firmware…

Cracking BitLocker encryption based on CVE-2023-21563 vulnerability

Analysis and exploitation of CVE-2025-4275 (Hydr0ph0bia), a Secure Boot trust-chain weakness where firmware variables are used to introduce…


CVE-2026-11499

jump over aslr attacking branch predictors to bypass aslr Technique

CVE Realtek SD card reader. CVE-2022-25477, CVE-2022-25478, CVE-2022-25479, CVE-2022-25480, CVE-2024-40432, CVE-2024-40431

Research and hands-on PoC of Spectre Variant 2 (CVE-2017-5715), a hardware side-channel vulnerability exploiting CPU speculative execution and branch…

This is a suite of tools/PoCs/exploits for cameras using the iCSee application. And yes - it can run NES games!
