
Flask-Unsign
Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.
ctfpassword-attackspenetration-testing+1
661

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Exploit the Redash weak secret key vulnerability (GHSA-g8xr-f424-h2rv) to generate password reset links for any user, enabling account takeover…

InfluxDB CVE-2019-20933 vulnerability exploit

CVE-2025-59390 and ThreadLocalRandom Inverse

A vulnerability can allow an attacker to guess the automatically generated development mode secret token.