Some exploits I've found, mostly PoCs for other ppl's stuff
Repositories
ticarpi repositories
Tooling (not mine) zipped for download. May contain malware. You have been warned...
A python decryption script for an unnamed cipher used by PUP/PUA-packed executables
A personal collection of password lists, rules, masks, processes and syntax for cracking passwords - particularly focused on domain accounts
Automation for Docker images
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens
This is a set of tips and reminders for pentesting processes and scripts/programs. Initially for personal use, but if anyone else finds the reminders useful, then enjoy! A few links for useful tools and files. Some tools written by me.
Details of my CVEs, disclosures, reporting from vulnerability research
Deriving RSA public keys from message-signature pairs
:triangular_ruler: A flexible two-column Jekyll theme. Perfect for personal sites, blogs, and portfolios hosted on GitHub or your own server.
A collection of web tools crafted for web app pentesting