
FOISted
MikroTik remote jailbreak for v6.x.x

MikroTik remote jailbreak for v6.x.x

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

Exploiting TP-Link Archer CR-700 Router. (Responsibly Disclosed to TP-Link)

A bunch of routers firmware images. Principally those that are not available and they do need to be extracted via JTAG, UART, desoldering flash or…

Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

A collection of my public security advisories.

NCC Group Template for the Microsoft Threat Modeling Tool 2016 for Automotive Security

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

Multi-threaded router fingerprinting tool that identifies web-exposed network devices by analyzing HTTP responses, headers, and favicon hashes for…

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

A TUI bluetooth utility for radar analysis and war driving 🦉

This repo has a blog post about my analysis for CVE-2018-19987 an authenticated OS command injection affecting multiple D-Link routers


Writeup for Tenda AC15 router firmware rehosting and remote command execution (CVE-2020-10987) exploit replication.

Hardware Hacking Cheatsheet

A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.


Or how I turn off my TV via a cronjob