
Loracrack
LoRaWAN session cracker - A PoC for exploiting weak or shared Application Keys

LoRaWAN session cracker - A PoC for exploiting weak or shared Application Keys

Multi-protocol honeypot simulator supporting 50+ network services with deep interaction, TCP/UDP/ICMP logging, JA3 fingerprinting, and virtual…

Primary Git Repository for the Zephyr Project. Zephyr is a new generation, scalable, optimized, secure RTOS for multiple hardware architectures.

Real world and CTFs exploiting web/binary POCs.

Curated collection of open specifications for AI-integrated vehicle systems, covering autonomy, perception, navigation, energy management, safety,…

Proof-of-concept exploit and analysis for command injection and hardcoded backdoor credentials in D-Link NAS devices, enabling unauthenticated remote…

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

PoC exploit for Dahua authentication bypass (CVE-2021-33044). Scans subnets, tests multiple CVEs, and dumps device configs via crafted cookies…

Bash script exploiting CVE-2018-9995 to extract credentials from vulnerable DVRs via web interface, supporting multiple DVR brands for automated…

Proof-of-concept exploits for CVE-2025-52688: unauthenticated command injection and arbitrary file read vulnerabilities in Alcatel AP13161 enterprise…

TP-LINK Multiple HTML Injection Vulnerabilities

Research project on heterogeneous IoT protocols modelling

This repo has a blog post about my analysis for CVE-2018-19987 an authenticated OS command injection affecting multiple D-Link routers

This project demonstrates the publicly disclosed CVE-2018-9995 vulnerability found in multiple embedded DVR devices.

Multiple Brother Devices: Multiple Vulnerabilities (CVE-2024-51977, CVE-2024-51978, CVE-2024-51979, CVE-2024-51980, CVE-2024-51981, CVE-2024-51982,…

Generates efficient IPv4 blocklists from Zeek network flows using multiple prioritization models (new, consistent, random forest) to identify…

Exploit tool for CVE-2018-9995 that retrieves DVR credentials via crafted HTTP request, targeting multiple DVR vendors for security testing.

Exploit tool for CVE-2018-9995 that extracts credentials from exposed DVR devices via HTTP request with cookie bypass, targeting multiple vendor…