A tool that detects unauthorized access vulnerabilities through passive proxies, leveraging mainstream AI systems such as Kimi, DeepSeek, GPT, and others.
-
Updated
Aug 19, 2026 - Go
A tool that detects unauthorized access vulnerabilities through passive proxies, leveraging mainstream AI systems such as Kimi, DeepSeek, GPT, and others.
Advisory for CVE-2020-28054 & stack based buffer overflow in IBM Tivoli Storage Manager
An intentionally vulnerable PHP web application designed for ethical hacking and cybersecurity training. Learn to exploit and secure vulnerabilities like SQL Injection, Authentication Bypass, and more in a controlled environment.
Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth
Four native bypass engines in one dependency-free Go binary - baseline fingerprinting separates real 403 bypasses from fake 200s. CONFIRMED findings ship with exact curl repro commands.
Italian technical writeup on a WordPress REST API featured_media authorization boundary issue
CVE-2026-25197: Authorization Bypass via IDOR — Gardyn Home Kit (ICSA-26-055-03)
🎓 Complete IDOR (Insecure Direct Object Reference) Guide: Beginner → Advanced
Static-analysis CLI (GitHub Action) that flags client-controlled tier/plan/role values reaching an entitlement decision without Stripe-webhook-verified gating.
Canonically Yours — signing one package, publishing another. Intigriti 0726 write-up. Cross-namespace read via JSON duplicate-key parser differential (Intigriti July 2026)
Add a description, image, and links to the authorization-bypass topic page so that developers can more easily learn about it.
To associate your repository with the authorization-bypass topic, visit your repo's landing page and select "manage topics."