Skip to content
View kOaDT's full-sized avatar
🍉
🍉

Block or report kOaDT

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kOaDT/README.md

AppSec & Web Developer

Header

TryHackMe   Root-Me


Vulnerabilities Reported (2)
Advisory CVE Severity Date Summary
GHSA-g747-7v24-2w4v - Medium 2026-08-21 OAuth2 state parameter is not validated on callback, allowing authorization code injection
GHSA-qrx8-9hc6-jvqg CVE-2026-32255 High (8.6) 2026-03-18 Unauthenticated SSRF in attachment download endpoint
CVE Proof of Concepts (3)
CVE Description ⭐ 🍴 👁️ 📥
CVE-2025-55182 This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React Server Components, also known as React2Shell. 15 3 5884 1786
CVE-2025-29927 This repository contains a POC and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware. 9 3 2793 1065
CVE-2026-32255 This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an open-source project management tool. 2 - 1090 391
Projects (5)
Project Description ⭐ 🍴 👁️ 📥
oss-oopssec-store Security training for the apps you actually ship. Open your browser and start hacking. 47 56 7448 56021
cyber-bot Threat intelligence platform: RSS aggregation, NVD CVE tracking, ENISA EUVD, databreaches, ... 7 1 261537 2337
hate-crimes-map This project aims to visualize hate crime data to bring visibility to crimes that are often invisible or normalized by society. 3 - 164 665
awesome-pentest-tools Open-source offensive security tools, plus a vendor-agnostic AI agent that runs authorized pentest engagements using only tools from this list. 3 2 61 277
crack-hash A fast, multi-threaded hash cracking tool written in Rust. This tool performs dictionary attacks against hashed passwords. 2 - 87 114
OSS Contributions (22)
Repository Description ⭐ 🍴
kanbn/kan The open source Trello alternative. 5703 493
ThePorgs/Exegol Fully featured and community-driven hacking environment 3098 287
OWASP/www-community OWASP Community Pages are a place where OWASP can accept community contributions for security-related content. 1411 848
OWASP/www-project-vulnerable-web-applications-directory The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available. 94 52
OWASP/OCSD OWASP Certified Secure-Software Developer 41 16
nilbuild/developer-roadmap Interactive roadmaps, guides and other educational content to help developers grow in their careers. 368338 44999
mermaid-js/mermaid Generation of diagrams like flowcharts or sequence diagrams from text in a similar manner as markdown 90450 9306
usebruno/bruno Opensource IDE For Exploring and Testing API's (lightweight alternative to Postman/Insomnia) 47230 2925
enaqx/awesome-pentest A collection of awesome penetration testing resources and tools 27302 4965
qazbnm456/awesome-web-security 🐶 A curated list of Web Security materials and resources. 13829 1823
infoslack/awesome-web-hacking A list of web application security 7281 1361
satnaing/astro-paper A minimal, accessible and SEO-friendly Astro blog theme. 5082 1100
husnainfareed/awesome-ethical-hacking-resources 😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing. 3784 561
lingdojo/kana-dojo Aesthetic, minimalist platform for learning Japanese inspired by Duolingo and Monkeytype, built with Next.js and sponsored by Vercel. Beginner-friendly with plenty of good first issues - all contributions are welcome! 3493 3433
beelzebub-labs/beelzebub A secure low code deception runtime framework, leveraging AI for System Virtualization. 2181 212
fabionoth/awesome-cyber-security A collection of awesome software, libraries, documents, books, resources and cools stuffs about security. 1958 270
vavkamil/awesome-vulnerable-apps Awesome Vulnerable Applications 1484 229
kaiiyer/awesome-vulnerable A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB. 1397 228
okhosting/awesome-cyber-security A curated list of cyber security resources and tools. 757 126
Grafikart/Grafikart.fr Dépôt pour la nouvelle version de Grafikart.fr 699 191
noraj/rawsec-cybersecurity-inventory An inventory of tools and resources about CyberSecurity that aims to help people to find everything related to CyberSecurity. 346 75
secnotes/awesome-cybersecurity A collection of awesome github repositories about security 83 13
Publications (1)
Title Platform Category Date
MCP Tool Poisoning OWASP article 2026-03-26
Github Metrics

TryHackMe Stats
Global Rank Top Streak
#12694 1% 777 days
TryHackMe Badges (51)
  • Networking Nerd — Completing the 'Network Fundamentals' module
  • 7 Day Streak — Achieving a 7 day hacking streak
  • Webbed — Understands how the world wide web works
  • World Wide Web — Completing the 'How The Web Works' module
  • cat linux.txt — Being competent in Linux
  • 30 Day Streak — Hacking for 30 days solid
  • OWASP Top 10 — Understanding every OWASP vulnerability
  • Hash Cracker — Cracking all those hashes
  • Metasploitable — Contains the knowledge to use Metasploit
  • Blue — Hacking into Windows via EternalBlue
  • Cyber Ready — Understanding impact of training on teams
  • Sword Apprentice — Completing the SQLMap room
  • Shield Apprentice — Completing the FlareVM room
  • 90 Day Streak — Hacking for 90 days in a row
  • Linux PrivEsc — Mastering Linux Privilege Escalation
  • Pentesting Principles — Completing the 'Introduction to Pentesting' module
  • Intro to Web Hacking — Completing the 'Introduction to Web Hacking' module
  • Advent of Cyber 2024 — Completing Advent of Cyber 2024!
  • Burp'ed — Completing the Burp Suite module
  • 180 Day Streak — Hacking for 180 days in a row
  • Authentication Striker — Used the Hammer to bypass authentication
  • SQL Slayer — Conquered Advanced SQL Injection
  • System Sniffer — Completed the File Path traversal room
  • OhSINT — Completing the OhSINT room
  • Client-Side Champ — Successfully exploited client-side vulnerabilities
  • Introduction to Security Engineering — Completed the Security Engineer Intro room!
  • Calculated Risk — _Completed the Risk Management room! _
  • 3 Day Streak — Achieving a 3 day hacking streak
  • Network and System Security — Finished the Auditing and Monitoring room!
  • Software Security — _Completed the OWASP API Security Top 10 rooms! _
  • 365 Day Streak — Hacking for 365 days in a row
  • The Course Awakens — Finishing the first room in the DevSecOps path!
  • Just have to deal with it — _Successfully managed a cyber crisis! _
  • Raffle Royalty — Participating in Hack2Win 2025!
  • /opt/m0th3r — Finishing Mother’s Secret!
  • Skilled Navigator — Finishing the Eviction challenge!
  • First Step into SOC — Explored emerging threats and SOC response
  • SOC Apprentice — Explored how a SOC team operates from inside
  • First alert closed — Closing your first alert
  • First scenario completed — Completing your first scenario
  • 100% true positive rate — Achieving 100% true positive rate in a scenario
  • 500 Day Streak — Hacking for 500 days in a row
  • Tooling Specialist — Adept in creating custom offensive tooling
  • Advent of Cyber 2025 — Completing Advent of Cyber 2025!
  • Model Compromise — Completed the LLM Attacks Module
  • Session Held — Completing 4 weekly missions in a row!
  • Security Awareness — Completing the cyber security awareness module
  • Adversarial Defence Ops — Trained to Defend, Built to Learn.
  • AI Odyssey — Taking part in the AI Odyssey event!
  • 750 Day Streak — Hacking for 750 days in a row
  • NoScopeRCE — Completing the NoScopeRCE room
TryHackMe Completed Rooms (361)
# Room Difficulty
1 Crack the hash easy
2 Pickle Rick easy
3 Blue easy
4 OhSINT easy
5 Basic Pentesting easy
6 Vulnversity easy
7 Simple CTF easy
8 Kenobi easy
9 Steel Mountain easy
10 Agent Sudo easy
11 LazyAdmin easy
12 Introductory Networking easy
13 Hydra easy
14 Common Linux Privesc easy
15 Network Services easy
16 Introductory Researching easy
17 What the Shell? easy
18 Hashing - Crypto 101 medium
19 Linux PrivEsc medium
20 Upload Vulnerabilities easy
21 Encryption - Crypto 101 medium
22 Bounty Hacker easy
23 OWASP Juice Shop easy
24 Overpass easy
25 Network Services 2 easy
26 RootMe easy
27 Tutorial easy
28 MITRE medium
29 Starting Out In Cyber Sec easy
30 Nmap easy
31 John the Ripper: The Basics easy
32 Linux Fundamentals Part 1 info
33 Linux Fundamentals Part 2 info
34 How Websites Work easy
35 Linux Fundamentals Part 3 info
36 Putting it all together easy
37 DNS in Detail easy
38 HTTP in Detail easy
39 Windows Fundamentals 1 info
40 Windows Fundamentals 2 info
41 What is Networking? info
42 Intro to LAN info
43 OSI Model info
44 Packets & Frames info
45 Extending Your Network info
46 Learning Cyber Security easy
47 Windows Fundamentals 3 info
48 Linux Privilege Escalation medium
49 Walking An Application easy
50 Pentesting Fundamentals easy
51 Principles of Security info
52 Metasploit: Exploitation easy
53 Content Discovery easy
54 Subdomain Enumeration easy
55 Authentication Bypass easy
56 Junior Security Analyst Intro easy
57 Passive Reconnaissance easy
58 Active Reconnaissance easy
59 Nmap Live Host Discovery medium
60 Nmap Basic Port Scans easy
61 Nmap Advanced Port Scans medium
62 Metasploit: Introduction easy
63 IDOR easy
64 Vulnerabilities 101 easy
65 Metasploit: Meterpreter easy
66 Intro to SSRF easy
67 Pyramid Of Pain easy
68 Intro to Cross-site Scripting easy
69 Nmap Post Port Scans medium
70 Cyber Kill Chain easy
71 Diamond Model easy
72 Vulnerability Capstone easy
73 Exploit Vulnerabilities easy
74 Protocols and Servers easy
75 SQL Injection medium
76 Command Injection easy
77 Net Sec Challenge easy
78 File Inclusion medium
79 Protocols and Servers 2 medium
80 Intro to Digital Forensics easy
81 Introduction to DevSecOps medium
82 Operating System Security easy
83 Lo-Fi easy
84 Network Security easy
85 Web Application Security easy
86 Unified Kill Chain easy
87 SSDLC medium
88 Security Operations easy
89 Careers in Cyber info
90 Windows Privilege Escalation medium
91 Wireshark: The Basics easy
92 Intro to Cyber Threat Intel easy
93 Introduction to SIEM easy
94 Active Directory Basics easy
95 Microsoft Windows Hardening easy
96 Security Principles easy
97 Secure Network Architecture medium
98 Active Directory Hardening medium
99 Introduction to Cryptography medium
100 Network Security Protocols medium
101 OWASP API Security Top 10 - 2 medium
102 OWASP API Security Top 10 - 1 medium
103 Intro to Cloud Security easy
104 Linux System Hardening medium
105 Virtualization and Containers easy
106 Vulnerability Management medium
107 DAST medium
108 Weaponizing Vulnerabilities medium
109 Identity and Access Management easy
110 Network Device Hardening medium
111 Threat Modelling medium
112 Governance & Regulation easy
113 Mother's Secret easy
114 Security Engineer Intro easy
115 SAST medium
116 Risk Management easy
117 Logging for Accountability easy
118 Traverse easy
119 Auditing and Monitoring easy
120 Intro to IR and IM easy
121 Becoming a First Responder info
122 Cyber Crisis Management easy
123 W1seGuy easy
124 Burp Suite: The Basics info
125 Burp Suite: Repeater info
126 Burp Suite: Intruder medium
127 Burp Suite: Other Modules easy
128 Burp Suite: Extensions easy
129 Eviction easy
130 Summit easy
131 Light easy
132 HTTP Request Smuggling easy
133 SSRF medium
134 The Sticker Shop easy
135 File Inclusion, Path Traversal medium
136 CSRF medium
137 XSS easy
138 CORS & SOP easy
139 Prototype Pollution medium
140 Snyk Open Source easy
141 Include medium
142 Moniker Link (CVE-2024-21413) easy
143 Snyk Code easy
144 Race Conditions medium
145 LDAP Injection easy
146 Whats Your Name? medium
147 DOM-Based Attacks easy
148 XXE Injection medium
149 Insecure Deserialisation medium
150 Windows Command Line easy
151 Search Skills easy
152 Server-side Template Injection medium
153 JWT Security easy
154 Nmap: The Basics easy
155 Networking Concepts easy
156 Tcpdump: The Basics easy
157 Networking Essentials easy
158 Networking Core Protocols easy
159 Networking Secure Protocols easy
160 Advanced SQL Injection medium
161 Incident Response Fundamentals easy
162 ORM Injection medium
163 NoSQL Injection easy
164 Logs Fundamentals easy
165 Enumeration & Brute Force easy
166 SOC Fundamentals easy
167 Digital Forensics Fundamentals easy
168 Session Management easy
169 Injectics medium
170 Firewall Fundamentals easy
171 OAuth Vulnerabilities medium
172 IDS Fundamentals easy
173 Multi-Factor Authentication easy
174 Vulnerability Scanner Overview easy
175 Hammer medium
176 CyberChef: The Basics easy
177 Public Key Cryptography Basics easy
178 Cryptography Basics easy
179 Hashing Basics easy
180 CAPA: The Basics easy
181 Windows PowerShell easy
182 FlareVM: Arsenal of Tools easy
183 REMnux: Getting Started easy
184 Linux Shells easy
185 Insecure Randomness easy
186 Gobuster: The Basics easy
187 Training Impact on Teams info
188 SQLMap: The Basics easy
189 Advent of Cyber 2024 easy
190 JavaScript Essentials easy
191 Web Application Basics easy
192 SQL Fundamentals easy
193 Shells Overview easy
194 Breaking Crypto the Simple Way easy
195 Erlang/OTP SSH: CVE-2025-32433 easy
196 Writing Pentest Reports easy
197 Cipher's Secret Message easy
198 Evil-GPT easy
199 Evil-GPT v2 easy
200 Roundcube: CVE-2025-49113 easy
201 Kali Machine easy
202 tmux easy
203 Hacking with PowerShell easy
204 Bebop easy
205 DVWA easy
206 Geolocating Images easy
207 Sudo Security Bypass info
208 Google Dorking easy
209 NIS - Linux Part I easy
210 Python Basics easy
211 Physical Security Intro easy
212 The Hacker Methodology easy
213 Getting Started easy
214 Introduction to Flask easy
215 Cryptography for Dummies easy
216 How to use TryHackMe easy
217 Learn and win prizes info
218 SQLMAP easy
219 Security Awareness info
220 Common Attacks easy
221 Red Team Fundamentals easy
222 Pwnkit: CVE-2021-4034 info
223 Threat Intelligence Tools easy
224 Spring4Shell: CVE-2022-22965 info
225 Intro to Containerisation easy
226 Atlassian CVE-2022-26134 easy
227 Broken Access Control easy
228 The Witch's Cauldron easy
229 Confluence CVE-2023-22515 easy
230 Become a Hacker easy
231 Length Extension Attacks medium
232 Padding Oracles medium
233 Phishing Basics easy
234 Custom Tooling Using Python easy
235 Custom Tooling using Burp hard
236 Tooling via Browser Automation easy
237 SOC L1 Alert Triage easy
238 SOC L1 Alert Reporting easy
239 Cyber Kill Chain medium
240 SOC Workbooks and Lookups easy
241 Attacking ECB Oracles hard
242 Next.js: CVE-2025-29927 easy
243 SOC Metrics and Objectives easy
244 The Building Blocks of AI easy
245 CAPTCHApocalypse medium
246 AI Forensics medium
247 Extract hard
248 AD: BadSuccessor medium
249 Sequence medium
250 ContAInment medium
251 Chaining Vulnerabilities easy
252 Voyage medium
253 Humans as Attack Vectors easy
254 Systems as Attack Vectors easy
255 SOC Role in Blue Team easy
256 Web Security Essentials easy
257 Hack2Win: How you can grab extra tickets info
258 Introduction to EDR easy
259 Input Manipulation & Prompt Injection easy
260 Data Integrity & Model Poisoning medium
261 LLM Output Handling and Privacy Risks easy
262 IDOR - Santa’s Little IDOR medium
263 Obfuscation - The Egg Shell File medium
264 XSS - Merry XSSMas easy
265 Passwords - A Cracking Christmas easy
266 SOC Alert Triaging - Tinsel Triage medium
267 Splunk Basics - Did you SIEM? medium
268 Phishing - Merry Clickmas easy
269 Prompt Injection - Sched-yule conflict easy
270 Linux CLI - Shells Bells easy
271 YARA Rules - YARA mean one! medium
272 Forensics - Registry Furensics medium
273 Exploitation with cURL - Hoperation Eggsploit easy
274 ICS/Modbus - Claus for Concern medium
275 Race Conditions - Toy to The World easy
276 Network Discovery - Scan-ta Clause easy
277 Containers - DoorDasher's Demise medium
278 CyberChef - Hoperation Save McSkidy medium
279 Phishing - Phishmas Greetings medium
280 AI in Security - old sAInt nick easy
281 Malware Analysis - Malhare.exe easy
282 C2 Detection - Command & Carol medium
283 AWS Security - S3cret Santa easy
284 Malware Analysis - Egg-xecutable medium
285 Web Attack Forensics - Drone Alone medium
286 Cloud Security Pitfalls easy
287 Juicy medium
288 Advent of Cyber Prep Track easy
289 OWASP Top 10 2025: IAAA Failures easy
290 OWASP Top 10 2025: Application Design Flaws easy
291 OWASP Top 10 2025: Insecure Data Handling easy
292 Django: CVE-2025-64459 easy
293 BankGPT easy
294 HealthGPT easy
295 React2Shell: CVE-2025-55182 easy
296 Virtualisation Basics easy
297 Operating Systems: Introduction easy
298 Linux CLI Basics easy
299 Data Representation easy
300 Data Encoding easy
301 JavaScript: Simple Demo medium
302 Python: Simple Demo easy
303 LLM Security medium
304 Windows Basics easy
305 Cloud Computing Fundamentals easy
306 Windows CLI Basics easy
307 The CIA Triad easy
308 Database SQL Basics easy
309 Recruit medium
310 Cryptography Concepts easy
311 Client-Server Basics easy
312 Understanding Vulnerability Databases easy
313 Become a Hacker easy
314 Become a Defender easy
315 n8n: CVE-2025-68613 easy
316 Offensive Security Intro easy
317 Inside a Computer System easy
318 GeoServer: CVE-2025-58360 medium
319 Support medium
320 Computer Types easy
321 Dive Into Pentesting easy
322 API Pentesting easy
323 Prompt Engineering easy
324 AI Models & Data medium
325 Walking An Application easy
326 Defensive Security Intro info
327 AI Threat Modelling medium
328 Securing AI Systems medium
329 CSRF Introduction easy
330 AI System Reconnaissance medium
331 Basic Vulnerability Identification Techniques easy
332 Penetration Testing Frameworks easy
333 Guided Pentest: Infrastructure easy
334 XSS Introduction medium
335 SQL Injection Introduction easy
336 Vulnerability Scanning Tools medium
337 Guided Pentest: Web easy
338 Web Server Attacks - I medium
339 AI Threat Modelling Assessment easy
340 AI Security Path Ticketing Event info
341 Web Server Attacks - II medium
342 Broken Authentication easy
343 Modern Web Stacks easy
344 Content Discovery easy
345 CVE-2026-46300: Fragnesia easy
346 CVE-2026-42945: Nginx Rift easy
347 NoScope: Finding RCE medium
348 The Concierge Knows Too Much easy
349 Room 404 easy
350 Complimentary easy
351 Packed Light easy
352 Beach Bar easy
353 Overheard at Breakfast easy
354 Do Not Disturb medium
355 Towel on the Sunbed medium
356 CryptoCabana medium
357 The Hollow Shell medium
358 Infinity Pool medium
359 After Hours medium
360 The Guestbook medium
361 Management Wants a Word hard
Certificates (124)

OSS OopsSec Store badge

Pinned Loading

  1. oss-oopssec-store oss-oopssec-store Public

    Security training for the apps you actually ship. Open your browser and start hacking.

    TypeScript 47 56

  2. OWASP/www-community OWASP/www-community Public

    OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

    HTML 1.4k 849

  3. ThePorgs/Exegol ThePorgs/Exegol Public

    Fully featured and community-driven hacking environment

    Python 3.1k 287

  4. OWASP/OCSD OWASP/OCSD Public

    OWASP Certified Secure-Software Developer

    41 16

  5. nilbuild/developer-roadmap nilbuild/developer-roadmap Public

    Interactive roadmaps, guides and other educational content to help developers grow in their careers.

    TypeScript 368k 45k

  6. OWASP/www-project-vulnerable-web-applications-directory OWASP/www-project-vulnerable-web-applications-directory Public

    The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.

    HTML 94 52