This is your work, valued

Potsdam

Hanno Böck

Elite
@hannob

TLS and E-Mail security consulting

snallygaster. Tool to scan for secret files on HTTP servers

2.1k

bashcheck. test script for shellshocker and related vulnerabilities

665

php-crashers. Example scripts that cause segfaults in PHP

440

vulns. Named vulnerabilities and their practical impact

436

meltdownspectre-patches. Summary of the patch status for Meltdown / Spectre

348

vacdec. Python script to decode the EU Covid-19 vaccine certificate

241

optionsbleed. Python

147

tlshelpers. A collection of scripts that help handling X.509 certificate and TLS issues

129

smtpsmug. Python

109

tls-what-can-go-wrong. TLS - what can go wrong?

108

hpkp. HTTP Public Key Pinning (HPKP) pin generation tools

71

apache-uaf. Apache use after free bug infos / ASAN stack traces

66

superfishy. Archive of software and other data involved in the Superfish / Komodia incident

62

fpmvuln. bash poc scripts to exploit open fpm ports

61

lecaa. Check for Let's Encrypt CAA issue

53

hackercon. List of Free Software and IT Security related conferences

52

bignum-fuzz. Code to fuzz bignum libraries

46

selftls. Sample application to let OpenSSL talk to itself (for fuzzing)

34

pgpecosystem. Scripts to parse and analyze pgp key server data

33

com2txt. com2txt tool (from 1993)

31

zipeinfo. ZIP encryption info

30

alphasecret. Find PNG files with suspicious data in alpha channel

28

ctgrab. Shell

25

pgpbugs. A history of PGP-related vulnerabilities

24

ed25519hetzner. Script to scan OpenSSH host key and known_hosts files for shared keys from server hoster Hetzner

19

mmapfail. Simple shell script to detect bad checks of mmap() return value

19

pwncloud. proof of concept to backdoor files from owncloud encryption module

18

svnscraper. bash script to download publicly available .svn directories

16

libfuzzer-examples. examples for libfuzzer

15

secpw. Secure random passwords in Javascript

14

ipmx. Python

13

badocspcert. Check for certs affected by July 2020 OCSP intermediate incident

13

jitsivuln. Check for jitis meet default password vulnerability

12

uudeview. Decoder and encoder for Base64 (MIME), uuencoded, xxencoded and Binhex files.

11

primecheck. Check Diffie Hellman group prime parameter

11

httpstime. Setting the system time over HTTPS

10

pypi-bad. Bad packages from the pypi repository

9

webminex. poc exploit for webmin backdoor (CVE-2019-15107 and CVE-2019-15231)

8

emailprotocols. An overview of E-Mail protocols and data formats

8

mbox2maildir. Script to convert between mbox and maildir format

8

asantoo. Overlay to use Gentoo with Address Sanitizer

8

rpter. Parse mails with reports from DMARC and SMTP TLS Reporting

7

silic. silic - simple link checker written in python

7

tmobile-login. Trivial bash script to log into Telekom / T-Mobile wireless lan

6

fritzbox-keys. private keys found on AVM Fritz!Box firmware images

6

rompager-check. Online and offline check tool for the RomPager HTTP server and vulnerable versions

6

geogrep. Find images by geo coordinate proximity

6

forti. Info on 2025 Fortinet/Fortigate leak

6

xssgame. PHP

5

exif2osm. Convert JPEG exif geotags to link on openstreetmap.org

5

crimesafe-csrf. Create CSRF tokens secure from compression attacks like CRIME/BREACH/TIME/HEIST

3

svgx. Shell script chaining various SVG optimization tools

3

rdrand-test. Testing the rdrand CPU instruction

3

rosproject-scripts. Scripts to compile ROS packages with compiler sanitizers

2

courier-libs. Courier Mail Server - shared libraries

1

alwaysdns. Python

1