
fitness-app
BLE-based Fitbit research tool for authentication replay, encrypted activity dump decryption, memory/firmware extraction, and custom firmware…

BLE-based Fitbit research tool for authentication replay, encrypted activity dump decryption, memory/firmware extraction, and custom firmware…

Local streaming tool for cheap WiFi cameras that bypasses cloud services and phone apps. Discovers cameras on your network, authenticates via PPPP…

This tool is used for encrypt backdoor,shellcode,socks5 proxy generation,Information retrieval and POC arrangement for various architecture devices

Flipper Zero app for infrared electronic shelf-label (ESL) protocol research, featuring custom image transmission, NFC tag scanning, and a web-based…

A Virtual environment for Pentesting IoT Devices

Reverse engineering research and custom firmware for Allwinner V3-based IoT cameras, including firmware parsers, an AVIOCTRL client, and a…

Toolkit for implant attack of IoT devices

IoT Malware Similarity Analysis Platform

my advisory, poc, slides and scripts related to IoT/protocol security

Original research and PoC for a pre-auth stack buffer overflow via unbounded sscanf scanset in the Netis NC63 ipFilterList handler

CVE-2025-70962 PoC

Security analysis toolkit for proprietary car protocols

MOC3ingbird Exploit for Live2D (CVE-2023-27566)

Program to decode radio transmissions from devices on the ISM bands (and other frequencies)

Run Radmin VPN on Linux via Wine — custom driver, TAP bridge, zero packet loss

An unofficial Humax IR4000HD terminal client with enhanced features.

rt26cx21x64.sys exploit (Realtek PCIe GbE/2.5GbE/5GbE family)

Independent IoT security research, vulnerability disclosures, and PoCs focusing on firmware analysis, hardware interfaces, and cryptographic flaws.