
modo
Curated collection of cybersecurity learning resources, CTF writeups, research papers, and practical labs for hands-on skill development across web…

Curated collection of cybersecurity learning resources, CTF writeups, research papers, and practical labs for hands-on skill development across web…

Companion labs to "An Exploration of JSON Interoperability Vulnerabilities"

Kurukshetra - A framework for teaching secure coding by means of interactive problem solving.

Analysis of two authentication bypass techniques for Apache Shiro (CVE-2020-17523) with a reproducible exploit environment and detailed root cause…

Collection of DEF CON 30 CTF challenge binaries, build scripts, and solve scripts for practicing binary exploitation and reverse engineering.

This is an intentionally vulnerable smart contract truffle deployment aimed at allowing those interested in smart contract security to exploit a wide…

Curated inventory of cybersecurity tools and resources covering penetration testing, forensics, OSINT, web security, malware analysis, cryptography,…

Lord Of Active Directory - automatic vulnerable active directory on AWS

A curated list of AI Security materials and resources for Pentesters, Bug Hunters, and Security Researchers.

A pure Rust reimplementation of libxml2

Deliberately vulnerable Node.js web application for practicing exploitation of SQL injection, XSS, IDOR, command injection, XXE, and deserialization…

Reproduction of CVE-2022-30190 (Follina) remote code execution vulnerability in Microsoft Office Word via malicious docx/rtf files with ms-msdt…

First iteration of ML based Feedback WAF

This is a container of web applications that work with OWASP Bug Bounty for Projects

Environment with vulnerable kernel for exploitation of the TEE driver (CVE-2021-44733)

CVE-2020-8163 - Remote code execution of user-provided local names in Rails

Helper scripts to remaster Linux Live CD images for the purpose of creating ready to use security wargames with pre-installed vulnerabilities to…

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.