Wellington, New Zealand

☃ Stephen Shkardoon ☃

Elite
@ss23

I annoy people on the IRC

fortitoken-mobile-registration. Python implementation of FortiToken registration and TOTP token extraction

97

entrust-identityguard-tools. Tools for playing with Entrust IdentityGuard soft tokens, such as decrypting QR codes and deriving OTP secrets

48

hid-iclass-key. Global key for HID iCLASS

43

ioncube-string-decoder. Hacky script(s) for decoding strings stored in the ioncube loader

28

access-control. A reference of the different types of access control card readers and which countries they're commonly found in

19

evilginx2. Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication

18

php-tutorial. A PHP Tutorial

12

Lyrics-Database. A nice database/site for lyrics

8

ioncube-archive. An archive of collected ioncuber encoders, loaders, and associated files

6

BusitBalanceViewer. Android application for viewing the balance of a Busit card (from Hamilton, New Zealand)

6

tribot-authentication. A set of fake scripts and documentation for faking an authentication server for tribot

5

startmate-mobile. Dart

5

php-help. Hopefully some nice docs written on simple PHP topics for people who join #php and want it

5

Pass-Store. Storing Password Securely

3

NokeFiddler. Android application to fiddle with Nokē locks

3

fido2-pin-disable-extension. An extension to transparently disable the PIN requirement on FIDO2/Passkeys implementations

3

vdf-runner. Tool for running Steam/SteamWorks `.vdf` install files manually

2

ngrok-cap. Spider and capture websites that are exposed through ngrok.com/ngrok.io

2

infibot-authentication. Set of scripts and files for running an Infibot authentication server

2

p0rk-crackling. Distributed password cracker for operating over high latency networks of loosely coupled hosts.

2

airplay-control-intercept. Scripts and control panel for intercepting Airplay traffic and inspecting/messing with it

2

safuck. safuck module for Unrealircd

2

xDrip. Nightscout version of xDrip+

1

ssh-hijack. A simple proof of concept for how to hijack sshd as a non-privileged user

1

gogs. Gogs is a painless self-hosted Git service

1

random-bruteforcer. Tool for bruteforcing the output of random()

1

zKillboard. zKillboard

1

metasploit-framework. Metasploit Framework

1

ghidra-findcrypt. Ghidra analysis plugin to locate cryptographic constants

1

teamviewer-optionshash. Information and tools for working with the TeamViewer OptionsPasswordHash value

1

google-photos-delete-tool. Tool for deleting all photos from the Google Photos

1

proxmark3. Proxmark 3

1

sasquatch. SilverStripe Mighty Ops Team CrispyFi Project

1

ssy. Junky repository for scanning shit, yo.

1

cisco-ironport-appliances-service. https://www.exploit-db.com/exploits/35887/ - The Cisco Ironport appliances service account password generator, updated for Linux support

1

test123.

1

proxmark3-rfidresearchgroup. RRG / Iceman repo, the most totally wicked repo around if you are into Proxmark3 and RFID hacking

1

Responder. Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.

1

keyvalues. Source engine KeyValue format parser (e.g. gameinfo.txt, vmt, vmf)

1

unicorn. Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, X86)

1

cryptopals. Go

1

CitrineJS. A bittorent tracker written in node

1

fuzzy-go-monster. Daemon to manage assignment of fuzzers when running afl

1

brute-extensions. Small script to verify which extensions return a 403 vs non 403 error for a given URL/domain

1
44
Apply