
jwt-hack
JSON Web Token Hack Toolkit

JSON Web Token Hack Toolkit

Rust-based GUI tool for WiFi security auditing: captures traffic, discovers clients, performs deauthentication attacks, captures handshakes, and…

SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.

Set of tools to audit SIP based VoIP Systems

GPU-accelerated SHA-256 rainbow table implementation based on CDP (Cyclic Digit-sum Projection) structural analysis. AMD RX 9070 XT, OpenCL + Vulkan.

CVE-2026-39031 — offline plaintext password recovery for Lansweeper lsrunase 2.0 / lsencrypt 2.0 via a hardcoded RC4 key. PoC + technical advisory.

Time-Based Blind SQL Injection Exploit for the OpenSIPs Control Panel (or my first CVE!)

Automated exploit for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple ≤2.2.9. Extracts admin credentials (username, email,…

A simple, reliable and reasonably fast network capture analyzer.

An open source batch script based WiFi Passview for Windows!

Research tool for studying vulnerable cryptographic key generation (brainwallet, PRNG, milksad, LCG, xorshift)

A tool which can be used to generate password list or dictionary from the details of the target

Generate customized Password/Passphrase wordlist based on target information

tool for generating wordlists or extending an existing one using mutations.

Domain Password Audit Tool for Pentesters

Laravel Crypto Killer Mass Scanner (CVE-2024-55555)

Unauthenticated time-based blind SQL injection exploit for CMS Made Simple <= 2.2.9. Extracts admin credentials and optionally cracks password hashes…

A Proof on Concept for CVE-2023-6063, a time-based blind SQL injection vulnerability in WP Fastest Cache ≤1.2.2.