Security Projects
Collection of cybersecurity projects on hardening, network defense, and offensive security.
🔍 No results. Try another filter.
Apache Hardening
Configuration of apache2.conf, security.conf and php.ini with recommended security parameters.
Command Injection & RFI/LFI
Exploitation and countermeasures for command injection and remote/local file inclusion vulnerabilities using OWASP Mutillidae and bWAPP.
SQLMap: SQL Injection
Using SQLMap with BurpSuite to extract data from vulnerable databases on DVWA: users, passwords, and SQL shell.
XSS: Cookie Theft & Fake Forms
Stealing credentials with Netcat, session cookie theft via XSS and defense with htmlspecialchars().
Manual SQL Injection: bWAPP & DVWA
Manual UNION-based exploitation on bWAPP and unhex() bypass on DVWA medium level.
Android Reversing: InsecureBankv2 & KGB Messenger
APK reverse engineering: Java extraction, smali modification and access control bypass with dex2jar and JD-GUI.
DIVA Audit: Android Vulnerabilities
Insecure Logging, Hardcoding, insecure storage in SharedPreferences, SQLite and SQL Injection demonstrated with ADB.
InsecureBankv2 APK Analysis
APK unpacking, exported activity invocation with am start, VirusTotal/Metadefender analysis and Android permissions.
DIVA Advanced: Access Control & Buffer Overflow
Exercises 9–13: PIN bypass, insecure Content Providers, hardcoded JNI key and buffer overflow.
Nmap: Network Reconnaissance & Scanning
SYN scan, OS/version detection, NSE vulnerability scripts, firewall evasion and result export.
Metasploit Framework
Finding and using exploits, Meterpreter payloads, post-exploitation, auxiliary modules and msfvenom.
Hydra: Brute Force Attacks
Brute force SSH, FTP, RDP, SMB and HTTP web forms. Practice on DVWA with session cookies.
Wireshark: Traffic Analysis
Traffic capture, BPF and display filters, cleartext credential extraction and ARP spoofing detection.
John the Ripper & Hashcat
Cracking MD5, SHA1, bcrypt and NTLM hashes with dictionary attacks, brute force and mutation rules.
Burp Suite: Web Interception & Testing
Proxy, Repeater, Intruder and Scanner. Complete OWASP testing flow: SQLi, XSS, IDOR and brute force.
CSRF & Clickjacking
Exploitation on DVWA, PoC creation, and countermeasures: CSRF tokens, SameSite cookies and X-Frame-Options.
Nikto & Dirb/Gobuster
Automated web vulnerability scanning and discovery of hidden directories and files.
XXE & Path Traversal
XXE payloads to read server files and SSRF, and Path Traversal exploits with filter bypass.
Firewall Configuration
Step-by-step firewall configuration using iptables and firewalld to protect network infrastructure.
Vulnerability Scanner
Vulnerability scanning tool built with Python for automated security assessments.
Network Monitoring
Deployment and configuration of Snort IDS for real-time traffic analysis and intrusion detection.
Secure Development
Collection of secure development guides for web applications, covering OWASP Top 10.
Incident Response Plan
Framework and playbook to manage security incidents from detection to recovery.
Gobuster & ffuf: Web Fuzzing
Directory, file, subdomain and VHost discovery via dictionary attacks with Gobuster and ffuf.
Linux Privilege Escalation
Privesc techniques with LinPEAS: SUID, misconfigured sudo, cron jobs, exposed credentials and dangerous groups.
Docker: Container Security
Container escapes, exposed secrets, Dockerfile hardening and image vulnerability scanning with Trivy.
Shodan: OSINT & Passive Recon
Advanced Shodan searches to find exposed services, CVEs in production and misconfigured devices worldwide.
Guides & Manuals
Step-by-step manuals to improve your security posture.