Skip to content

Navigation Menu

Sign in
Sign up
@kOaDT
kOaDT
Follow
🍉
Exploring cybersecurity through vulnerability research, CTF competitions, and open-source security tool.
  • France

Block or report kOaDT

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kOaDT /README.md

AppSec & Web Developer

Header

TryHackMe Root-Me


Vulnerabilities Reported (2)
Advisory CVE Severity Date Summary
GHSA-g747-7v24-2w4v - Medium 2026年08月21日 OAuth2 state parameter is not validated on callback, allowing authorization code injection
GHSA-qrx8-9hc6-jvqg CVE-2026-32255 High (8.6) 2026年03月18日 Unauthenticated SSRF in attachment download endpoint
CVE Proof of Concepts (3)
CVE Description 🍴 👁️ 📥
CVE-2025-55182 This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React Server Components, also known as React2Shell. 15 3 5733 1714
CVE-2025-29927 This repository contains a POC and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware. 8 3 2593 967
CVE-2026-32255 This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an open-source project management tool. 2 - 1058 362
Projects (5)
Project Description 🍴 👁️ 📥
oss-oopssec-store Security training for the apps you actually ship. Open your browser and start hacking. 42 52 6713 54494
cyber-bot Threat intelligence platform: RSS aggregation, NVD CVE tracking, ENISA EUVD, databreaches, ... 7 1 261537 2151
hate-crimes-map This project aims to visualize hate crime data to bring visibility to crimes that are often invisible or normalized by society. 3 - 156 577
awesome-pentest-tools Open-source offensive security tools, plus a vendor-agnostic AI agent that runs authorized pentest engagements using only tools from this list. 3 2 37 258
crack-hash A fast, multi-threaded hash cracking tool written in Rust. This tool performs dictionary attacks against hashed passwords. 2 - 82 62
OSS Contributions (21)
Repository Description 🍴
kanbn/kan The open source Trello alternative. 5590 462
ThePorgs/Exegol Fully featured and community-driven hacking environment 3078 287
beelzebub-labs/beelzebub A secure low code deception runtime framework, leveraging AI for System Virtualization. 2170 207
OWASP/www-community OWASP Community Pages are a place where OWASP can accept community contributions for security-related content. 1409 843
OWASP/www-project-vulnerable-web-applications-directory The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available. 94 52
nilbuild/developer-roadmap Interactive roadmaps, guides and other educational content to help developers grow in their careers. 366538 44902
mermaid-js/mermaid Generation of diagrams like flowcharts or sequence diagrams from text in a similar manner as markdown 90148 9235
usebruno/bruno Opensource IDE For Exploring and Testing API's (lightweight alternative to Postman/Insomnia) 46816 2853
enaqx/awesome-pentest A collection of awesome penetration testing resources, tools and other shiny things 27143 4940
qazbnm456/awesome-web-security 🐶 A curated list of Web Security materials and resources. 13777 1816
infoslack/awesome-web-hacking A list of web application security 7261 1360
satnaing/astro-paper A minimal, accessible and SEO-friendly Astro blog theme. 5027 1095
husnainfareed/awesome-ethical-hacking-resources 😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing. 3758 561
lingdojo/kana-dojo Aesthetic, minimalist platform for learning Japanese inspired by Duolingo and Monkeytype, built with Next.js and sponsored by Vercel. Beginner-friendly with plenty of good first issues - all contributions are welcome! 3330 3218
fabionoth/awesome-cyber-security A collection of awesome software, libraries, documents, books, resources and cools stuffs about security. 1941 268
vavkamil/awesome-vulnerable-apps Awesome Vulnerable Applications 1480 226
kaiiyer/awesome-vulnerable A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB. 1391 227
okhosting/awesome-cyber-security A curated list of cyber security resources and tools. 731 119
Grafikart/Grafikart.fr Dépôt pour la nouvelle version de Grafikart.fr 699 190
noraj/rawsec-cybersecurity-inventory An inventory of tools and resources about CyberSecurity that aims to help people to find everything related to CyberSecurity. 345 75
secnotes/awesome-cybersecurity A collection of awesome github repositories about security 81 10
Publications (1)
Title Platform Category Date
MCP Tool Poisoning OWASP article 2026年03月26日
Github Metrics

TryHackMe Stats
Global Rank Top Streak
#12777 1% 755 days
TryHackMe Badges (50)
  • Networking NerdCompleting the 'Network Fundamentals' module
  • 7 Day StreakAchieving a 7 day hacking streak
  • WebbedUnderstands how the world wide web works
  • World Wide WebCompleting the 'How The Web Works' module
  • cat linux.txtBeing competent in Linux
  • 30 Day StreakHacking for 30 days solid
  • OWASP Top 10Understanding every OWASP vulnerability
  • Hash CrackerCracking all those hashes
  • MetasploitableContains the knowledge to use Metasploit
  • BlueHacking into Windows via EternalBlue
  • Cyber ReadyUnderstanding impact of training on teams
  • Sword ApprenticeCompleting the SQLMap room
  • Shield ApprenticeCompleting the FlareVM room
  • 90 Day StreakHacking for 90 days in a row
  • Linux PrivEscMastering Linux Privilege Escalation
  • Pentesting PrinciplesCompleting the 'Introduction to Pentesting' module
  • Intro to Web HackingCompleting the 'Introduction to Web Hacking' module
  • Advent of Cyber 2024Completing Advent of Cyber 2024!
  • Burp'edCompleting the Burp Suite module
  • 180 Day StreakHacking for 180 days in a row
  • Authentication StrikerUsed the Hammer to bypass authentication
  • SQL SlayerConquered Advanced SQL Injection
  • System SnifferCompleted the File Path traversal room
  • OhSINTCompleting the OhSINT room
  • Client-Side ChampSuccessfully exploited client-side vulnerabilities
  • Introduction to Security EngineeringCompleted the Security Engineer Intro room!
  • Calculated Risk — _Completed the Risk Management room! _
  • 3 Day StreakAchieving a 3 day hacking streak
  • Network and System SecurityFinished the Auditing and Monitoring room!
  • Software Security — _Completed the OWASP API Security Top 10 rooms! _
  • 365 Day StreakHacking for 365 days in a row
  • The Course AwakensFinishing the first room in the DevSecOps path!
  • Just have to deal with it — _Successfully managed a cyber crisis! _
  • Raffle RoyaltyParticipating in Hack2Win 2025!
  • /opt/m0th3rFinishing Mother’s Secret!
  • Skilled NavigatorFinishing the Eviction challenge!
  • First Step into SOCExplored emerging threats and SOC response
  • SOC ApprenticeExplored how a SOC team operates from inside
  • First alert closedClosing your first alert
  • First scenario completedCompleting your first scenario
  • 100% true positive rateAchieving 100% true positive rate in a scenario
  • 500 Day StreakHacking for 500 days in a row
  • Tooling SpecialistAdept in creating custom offensive tooling
  • Advent of Cyber 2025Completing Advent of Cyber 2025!
  • Model CompromiseCompleted the LLM Attacks Module
  • Session HeldCompleting 4 weekly missions in a row!
  • Security AwarenessCompleting the cyber security awareness module
  • Adversarial Defence OpsTrained to Defend, Built to Learn.
  • AI OdysseyTaking part in the AI Odyssey event!
  • 750 Day StreakHacking for 750 days in a row
TryHackMe Completed Rooms (351)
# Room Difficulty
1 Crack the hash easy
2 Pickle Rick easy
3 Blue easy
4 OhSINT easy
5 Basic Pentesting easy
6 Vulnversity easy
7 Simple CTF easy
8 Kenobi easy
9 Steel Mountain easy
10 Agent Sudo easy
11 LazyAdmin easy
12 Introductory Networking easy
13 Common Linux Privesc easy
14 Network Services easy
15 Introductory Researching easy
16 What the Shell? easy
17 Hashing - Crypto 101 medium
18 Linux PrivEsc medium
19 Upload Vulnerabilities easy
20 Encryption - Crypto 101 medium
21 Bounty Hacker easy
22 OWASP Juice Shop easy
23 Overpass easy
24 Network Services 2 easy
25 RootMe easy
26 Tutorial easy
27 MITRE medium
28 Starting Out In Cyber Sec easy
29 Nmap easy
30 John the Ripper: The Basics easy
31 Linux Fundamentals Part 1 info
32 Linux Fundamentals Part 2 info
33 How Websites Work easy
34 Linux Fundamentals Part 3 info
35 Putting it all together easy
36 DNS in Detail easy
37 HTTP in Detail easy
38 Windows Fundamentals 1 info
39 Windows Fundamentals 2 info
40 What is Networking? info
41 Intro to LAN info
42 OSI Model info
43 Packets & Frames info
44 Extending Your Network info
45 Learning Cyber Security easy
46 Windows Fundamentals 3 info
47 Linux Privilege Escalation medium
48 Walking An Application easy
49 Pentesting Fundamentals easy
50 Principles of Security info
51 Metasploit: Exploitation easy
52 Content Discovery easy
53 Subdomain Enumeration easy
54 Authentication Bypass easy
55 Junior Security Analyst Intro easy
56 Passive Reconnaissance easy
57 Active Reconnaissance easy
58 Nmap Live Host Discovery medium
59 Nmap Basic Port Scans easy
60 Nmap Advanced Port Scans medium
61 Metasploit: Introduction easy
62 IDOR easy
63 Vulnerabilities 101 easy
64 Metasploit: Meterpreter easy
65 Intro to SSRF easy
66 Pyramid Of Pain easy
67 Intro to Cross-site Scripting easy
68 Nmap Post Port Scans medium
69 Cyber Kill Chain easy
70 Diamond Model easy
71 Vulnerability Capstone easy
72 Exploit Vulnerabilities easy
73 Protocols and Servers easy
74 SQL Injection medium
75 Command Injection easy
76 Net Sec Challenge easy
77 File Inclusion medium
78 Protocols and Servers 2 medium
79 Threat Intelligence Tools easy
80 Intro to Digital Forensics easy
81 Introduction to DevSecOps medium
82 Operating System Security easy
83 Lo-Fi easy
84 Network Security easy
85 Web Application Security easy
86 Unified Kill Chain easy
87 SSDLC medium
88 Security Operations easy
89 Careers in Cyber info
90 Windows Privilege Escalation medium
91 Wireshark: The Basics easy
92 Intro to Cyber Threat Intel easy
93 Introduction to SIEM easy
94 Active Directory Basics easy
95 Microsoft Windows Hardening easy
96 Security Principles easy
97 Secure Network Architecture medium
98 Active Directory Hardening medium
99 Introduction to Cryptography medium
100 Network Security Protocols medium
101 OWASP API Security Top 10 - 2 medium
102 OWASP API Security Top 10 - 1 medium
103 Intro to Cloud Security easy
104 Linux System Hardening medium
105 Virtualization and Containers easy
106 Vulnerability Management medium
107 DAST medium
108 Weaponizing Vulnerabilities medium
109 Identity and Access Management easy
110 Network Device Hardening medium
111 Threat Modelling medium
112 Governance & Regulation easy
113 Mother's Secret easy
114 Security Engineer Intro easy
115 SAST medium
116 Risk Management easy
117 Logging for Accountability easy
118 Traverse easy
119 Auditing and Monitoring easy
120 Intro to IR and IM easy
121 Becoming a First Responder info
122 Cyber Crisis Management easy
123 W1seGuy easy
124 Burp Suite: The Basics info
125 Burp Suite: Repeater info
126 Burp Suite: Intruder medium
127 Burp Suite: Other Modules easy
128 Burp Suite: Extensions easy
129 Eviction easy
130 Summit easy
131 Light easy
132 HTTP Request Smuggling easy
133 SSRF medium
134 The Sticker Shop easy
135 File Inclusion, Path Traversal medium
136 CSRF medium
137 XSS easy
138 CORS & SOP easy
139 Prototype Pollution medium
140 Snyk Open Source easy
141 Include medium
142 Moniker Link (CVE-2024-21413) easy
143 Snyk Code easy
144 Race Conditions medium
145 LDAP Injection easy
146 Whats Your Name? medium
147 DOM-Based Attacks easy
148 XXE Injection medium
149 Insecure Deserialisation medium
150 Windows Command Line easy
151 Search Skills easy
152 Server-side Template Injection medium
153 JWT Security easy
154 Nmap: The Basics easy
155 Networking Concepts easy
156 Tcpdump: The Basics easy
157 Networking Essentials easy
158 Networking Core Protocols easy
159 Networking Secure Protocols easy
160 Advanced SQL Injection medium
161 Incident Response Fundamentals easy
162 ORM Injection medium
163 NoSQL Injection easy
164 Logs Fundamentals easy
165 Enumeration & Brute Force easy
166 SOC Fundamentals easy
167 Digital Forensics Fundamentals easy
168 Session Management easy
169 Injectics medium
170 Firewall Fundamentals easy
171 OAuth Vulnerabilities medium
172 IDS Fundamentals easy
173 Multi-Factor Authentication easy
174 Vulnerability Scanner Overview easy
175 Hammer medium
176 CyberChef: The Basics easy
177 Public Key Cryptography Basics easy
178 Cryptography Basics easy
179 Hashing Basics easy
180 CAPA: The Basics easy
181 Windows PowerShell easy
182 FlareVM: Arsenal of Tools easy
183 REMnux: Getting Started easy
184 Linux Shells easy
185 Insecure Randomness easy
186 Gobuster: The Basics easy
187 Training Impact on Teams info
188 SQLMap: The Basics easy
189 Advent of Cyber 2024 easy
190 JavaScript Essentials easy
191 Web Application Basics easy
192 SQL Fundamentals easy
193 Shells Overview easy
194 Breaking Crypto the Simple Way easy
195 Erlang/OTP SSH: CVE-2025-32433 easy
196 Writing Pentest Reports easy
197 Cipher's Secret Message easy
198 Evil-GPT easy
199 Evil-GPT v2 easy
200 Roundcube: CVE-2025-49113 easy
201 Kali Machine easy
202 tmux easy
203 Hacking with PowerShell easy
204 Bebop easy
205 DVWA easy
206 Geolocating Images easy
207 Sudo Security Bypass info
208 Google Dorking easy
209 NIS - Linux Part I easy
210 Python Basics easy
211 Physical Security Intro easy
212 The Hacker Methodology easy
213 Getting Started easy
214 Introduction to Flask easy
215 Cryptography for Dummies easy
216 How to use TryHackMe easy
217 Learn and win prizes info
218 SQLMAP easy
219 Security Awareness info
220 Common Attacks easy
221 Red Team Fundamentals easy
222 Pwnkit: CVE-2021-4034 info
223 Spring4Shell: CVE-2022-22965 info
224 Intro to Containerisation easy
225 Atlassian CVE-2022-26134 easy
226 Broken Access Control easy
227 The Witch's Cauldron easy
228 Confluence CVE-2023-22515 easy
229 Become a Hacker easy
230 Length Extension Attacks medium
231 Padding Oracles medium
232 Phishing Basics easy
233 Custom Tooling Using Python easy
234 Custom Tooling using Burp hard
235 Tooling via Browser Automation easy
236 SOC L1 Alert Triage easy
237 SOC L1 Alert Reporting easy
238 Cyber Kill Chain medium
239 SOC Workbooks and Lookups easy
240 Attacking ECB Oracles hard
241 Next.js: CVE-2025-29927 easy
242 SOC Metrics and Objectives easy
243 The Building Blocks of AI easy
244 CAPTCHApocalypse medium
245 AI Forensics medium
246 Extract hard
247 Sequence medium
248 ContAInment medium
249 Chaining Vulnerabilities easy
250 Voyage medium
251 Humans as Attack Vectors easy
252 Systems as Attack Vectors easy
253 SOC Role in Blue Team easy
254 Web Security Essentials easy
255 Hack2Win: How you can grab extra tickets info
256 Introduction to EDR easy
257 Input Manipulation & Prompt Injection easy
258 Data Integrity & Model Poisoning medium
259 LLM Output Handling and Privacy Risks easy
260 IDOR - Santa’s Little IDOR medium
261 Obfuscation - The Egg Shell File medium
262 XSS - Merry XSSMas easy
263 Passwords - A Cracking Christmas easy
264 SOC Alert Triaging - Tinsel Triage medium
265 Splunk Basics - Did you SIEM? medium
266 Phishing - Merry Clickmas easy
267 Prompt Injection - Sched-yule conflict easy
268 Linux CLI - Shells Bells easy
269 YARA Rules - YARA mean one! medium
270 Forensics - Registry Furensics medium
271 Exploitation with cURL - Hoperation Eggsploit easy
272 ICS/Modbus - Claus for Concern medium
273 Race Conditions - Toy to The World easy
274 Network Discovery - Scan-ta Clause easy
275 Containers - DoorDasher's Demise medium
276 CyberChef - Hoperation Save McSkidy medium
277 Phishing - Phishmas Greetings medium
278 AI in Security - old sAInt nick easy
279 Malware Analysis - Malhare.exe easy
280 C2 Detection - Command & Carol medium
281 AWS Security - S3cret Santa easy
282 Malware Analysis - Egg-xecutable medium
283 Web Attack Forensics - Drone Alone medium
284 Cloud Security Pitfalls easy
285 Juicy medium
286 Advent of Cyber Prep Track easy
287 OWASP Top 10 2025: Insecure Data Handling easy
288 Django: CVE-2025-64459 easy
289 BankGPT easy
290 HealthGPT easy
291 React2Shell: CVE-2025-55182 easy
292 Virtualisation Basics easy
293 Operating Systems: Introduction easy
294 Linux CLI Basics easy
295 Data Representation easy
296 Data Encoding easy
297 JavaScript: Simple Demo medium
298 Python: Simple Demo easy
299 LLM Security medium
300 Windows Basics easy
301 Cloud Computing Fundamentals easy
302 Windows CLI Basics easy
303 The CIA Triad easy
304 Database SQL Basics easy
305 Recruit medium
306 Cryptography Concepts easy
307 Client-Server Basics easy
308 Become a Hacker easy
309 Become a Defender easy
310 n8n: CVE-2025-68613 easy
311 Offensive Security Intro easy
312 Inside a Computer System easy
313 GeoServer: CVE-2025-58360 medium
314 Support medium
315 Computer Types easy
316 Dive Into Pentesting easy
317 API Pentesting easy
318 Prompt Engineering easy
319 AI Models & Data medium
320 Walking An Application easy
321 Defensive Security Intro info
322 AI Threat Modelling medium
323 Securing AI Systems medium
324 CSRF Introduction easy
325 AI System Reconnaissance medium
326 Penetration Testing Frameworks easy
327 Guided Pentest: Infrastructure easy
328 XSS Introduction medium
329 SQL Injection Introduction easy
330 Guided Pentest: Web easy
331 Web Server Attacks - I medium
332 AI Threat Modelling Assessment easy
333 AI Security Path Ticketing Event info
334 Web Server Attacks - II medium
335 Broken Authentication easy
336 Modern Web Stacks easy
337 Content Discovery easy
338 The Concierge Knows Too Much easy
339 Room 404 easy
340 Complimentary easy
341 Packed Light easy
342 Beach Bar easy
343 Overheard at Breakfast easy
344 Do Not Disturb medium
345 Towel on the Sunbed medium
346 CryptoCabana medium
347 The Hollow Shell medium
348 Infinity Pool medium
349 After Hours medium
350 The Guestbook medium
351 Management Wants a Word hard
Certificates (124)

Pinned Loading

  1. oss-oopssec-store oss-oopssec-store Public

    Security training for the apps you actually ship. Open your browser and start hacking.

    TypeScript 43 52

  2. OWASP/www-community OWASP/www-community Public

    OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

    HTML 1.4k 844

  3. ThePorgs/Exegol ThePorgs/Exegol Public

    Fully featured and community-driven hacking environment

    Python 3.1k 286

  4. OWASP/www-project-vulnerable-web-applications-directory OWASP/www-project-vulnerable-web-applications-directory Public

    The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.

    HTML 94 52

  5. nilbuild/developer-roadmap nilbuild/developer-roadmap Public

    Interactive roadmaps, guides and other educational content to help developers grow in their careers.

    TypeScript 367k 44.9k

  6. poc-cve-2025-55182 poc-cve-2025-55182 Public

    This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React Server Components, also known as React2Shell.

    TypeScript 15 3

AltStyle によって変換されたページ (->オリジナル) /