
Politician
Modern WiFi auditing library for ESP32 using advanced 802.11 techniques. Captures WPA/WPA2/WPA3 handshakes via PMKID extraction and CSA injection…

Modern WiFi auditing library for ESP32 using advanced 802.11 techniques. Captures WPA/WPA2/WPA3 handshakes via PMKID extraction and CSA injection…

RouterOS security research toolkit with Winbox honeypot, scanner, brute-force tools, NPK firmware modifier, and proof-of-concept exploits for…

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

Tool to exploit CVE-2018-13341 and recover hidden account password on Crestron devices

code to reverse vxworks 5.x password hashes

Extracts hardware random keys from NEC Aterm router firmware images and QR codes to generate valid passwords for gaining shell access.

Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.

Documentation and reproduction steps for CVE-2022-24693: hardcoded credentials in Baicells Nova436Q and Neutrino 430 firmware, enabling remote SSH…

Proof-of-concept exploit for CVE-2024-22894, demonstrating 3DES-encrypted root password extraction from Alpha Innotec/Novelan heatpump firmware,…

Python3 exploit for CVE-2018-14847, an unauthenticated path traversal in MikroTik Winbox that extracts and decrypts admin credentials from user.dat.

Proof-of-concept exploit for CVE-2024-44815 demonstrating extraction of plaintext router credentials from SPI flash via hardware teardown, UART…