Skip to content
View kOaDT's full-sized avatar

Block or report kOaDT

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kOaDT/README.md

AppSec & Web Developer

Header

TryHackMe   Root-Me


Vulnerabilities Reported (2)
Advisory CVE Severity Date Summary
GHSA-g747-7v24-2w4v - Medium 2026-08-21 OAuth2 state parameter is not validated on callback, allowing authorization code injection
GHSA-qrx8-9hc6-jvqg CVE-2026-32255 High (8.6) 2026-03-18 Unauthenticated SSRF in attachment download endpoint
CVE Proof of Concepts (3)
CVE Description ⭐ 🍴 👁️ 📥
CVE-2025-55182 This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React Server Components, also known as React2Shell. 15 3 5937 1814
CVE-2025-29927 This repository contains a POC and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware. 9 3 2855 1101
CVE-2026-32255 This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an open-source project management tool. 2 - 1099 409
Projects (5)
Project Description ⭐ 🍴 👁️ 📥
oss-oopssec-store Security training for the apps you actually ship. Open your browser and start hacking. 50 56 7672 56471
cyber-bot Threat intelligence platform: RSS aggregation, NVD CVE tracking, ENISA EUVD, databreaches, ... 7 1 261537 2401
hate-crimes-map This project aims to visualize hate crime data to bring visibility to crimes that are often invisible or normalized by society. 3 - 167 670
awesome-pentest-tools Open-source offensive security tools, plus a vendor-agnostic AI agent that runs authorized pentest engagements using only tools from this list. 3 2 71 303
crack-hash A fast, multi-threaded hash cracking tool written in Rust. This tool performs dictionary attacks against hashed passwords. 2 - 93 277
OSS Contributions (23)
Repository Description ⭐ 🍴
kanbn/kan The open source Trello alternative. 5736 499
ThePorgs/Exegol Fully featured and community-driven hacking environment 3105 288
OWASP/www-community OWASP Community Pages are a place where OWASP can accept community contributions for security-related content. 1411 852
OWASP/www-project-vulnerable-web-applications-directory The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available. 94 52
OWASP/OCSD OWASP Certified Secure-Software Developer 42 16
nilbuild/developer-roadmap Interactive roadmaps, guides and other educational content to help developers grow in their careers. 369037 45049
mermaid-js/mermaid Generation of diagrams like flowcharts or sequence diagrams from text in a similar manner as markdown 90571 9325
usebruno/bruno Opensource IDE For Exploring and Testing API's (lightweight alternative to Postman/Insomnia) 47374 2954
enaqx/awesome-pentest A collection of awesome penetration testing resources and tools 27356 4974
qazbnm456/awesome-web-security 🐶 A curated list of Web Security materials and resources. 13857 1823
infoslack/awesome-web-hacking A list of web application security 7285 1365
satnaing/astro-paper A minimal, accessible and SEO-friendly Astro blog theme. 5098 1110
husnainfareed/awesome-ethical-hacking-resources 😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing. 3789 562
lingdojo/kana-dojo Aesthetic, minimalist platform for learning Japanese inspired by Duolingo and Monkeytype, built with Next.js and sponsored by Vercel. Beginner-friendly with plenty of good first issues - all contributions are welcome! 3572 3539
beelzebub-labs/beelzebub A secure low code deception runtime framework, leveraging AI for System Virtualization. 2190 214
fabionoth/awesome-cyber-security A collection of awesome software, libraries, documents, books, resources and cools stuffs about security. 1966 269
vavkamil/awesome-vulnerable-apps Awesome Vulnerable Applications 1487 231
kaiiyer/awesome-vulnerable A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB. 1401 229
okhosting/awesome-cyber-security A curated list of cyber security resources and tools. 765 128
Grafikart/Grafikart.fr Dépôt pour la nouvelle version de Grafikart.fr 699 191
noraj/rawsec-cybersecurity-inventory An inventory of tools and resources about CyberSecurity that aims to help people to find everything related to CyberSecurity. 345 75
onestlatech/onestlatech.github.io ✊ Manifeste des travailleuses et travailleurs du numérique pour une autre réforme des retraites 171 247
secnotes/awesome-cybersecurity A collection of awesome github repositories about security 84 13
Publications (1)
Title Platform Category Date
MCP Tool Poisoning OWASP article 2026-03-26
Github Metrics

TryHackMe Stats
Global Rank Top Streak
#12566 1% 786 days
TryHackMe Badges (51)
  • Networking Nerd — Completing the 'Network Fundamentals' module
  • 7 Day Streak — Achieving a 7 day hacking streak
  • Webbed — Understands how the world wide web works
  • World Wide Web — Completing the 'How The Web Works' module
  • cat linux.txt — Being competent in Linux
  • 30 Day Streak — Hacking for 30 days solid
  • OWASP Top 10 — Understanding every OWASP vulnerability
  • Hash Cracker — Cracking all those hashes
  • Metasploitable — Contains the knowledge to use Metasploit
  • Blue — Hacking into Windows via EternalBlue
  • Cyber Ready — Understanding impact of training on teams
  • Sword Apprentice — Completing the SQLMap room
  • Shield Apprentice — Completing the FlareVM room
  • 90 Day Streak — Hacking for 90 days in a row
  • Linux PrivEsc — Mastering Linux Privilege Escalation
  • Pentesting Principles — Completing the 'Introduction to Pentesting' module
  • Intro to Web Hacking — Completing the 'Introduction to Web Hacking' module
  • Advent of Cyber 2024 — Completing Advent of Cyber 2024!
  • Burp'ed — Completing the Burp Suite module
  • 180 Day Streak — Hacking for 180 days in a row
  • Authentication Striker — Used the Hammer to bypass authentication
  • SQL Slayer — Conquered Advanced SQL Injection
  • System Sniffer — Completed the File Path traversal room
  • OhSINT — Completing the OhSINT room
  • Client-Side Champ — Successfully exploited client-side vulnerabilities
  • Introduction to Security Engineering — Completed the Security Engineer Intro room!
  • Calculated Risk — _Completed the Risk Management room! _
  • 3 Day Streak — Achieving a 3 day hacking streak
  • Network and System Security — Finished the Auditing and Monitoring room!
  • Software Security — _Completed the OWASP API Security Top 10 rooms! _
  • 365 Day Streak — Hacking for 365 days in a row
  • The Course Awakens — Finishing the first room in the DevSecOps path!
  • Just have to deal with it — _Successfully managed a cyber crisis! _
  • Raffle Royalty — Participating in Hack2Win 2025!
  • /opt/m0th3r — Finishing Mother’s Secret!
  • Skilled Navigator — Finishing the Eviction challenge!
  • First Step into SOC — Explored emerging threats and SOC response
  • SOC Apprentice — Explored how a SOC team operates from inside
  • First alert closed — Closing your first alert
  • First scenario completed — Completing your first scenario
  • 100% true positive rate — Achieving 100% true positive rate in a scenario
  • 500 Day Streak — Hacking for 500 days in a row
  • Tooling Specialist — Adept in creating custom offensive tooling
  • Advent of Cyber 2025 — Completing Advent of Cyber 2025!
  • Model Compromise — Completed the LLM Attacks Module
  • Session Held — Completing 4 weekly missions in a row!
  • Security Awareness — Completing the cyber security awareness module
  • Adversarial Defence Ops — Trained to Defend, Built to Learn.
  • AI Odyssey — Taking part in the AI Odyssey event!
  • 750 Day Streak — Hacking for 750 days in a row
  • NoScopeRCE — Completing the NoScopeRCE room
TryHackMe Completed Rooms (364)
# Room Difficulty
1 Crack the hash easy
2 Pickle Rick easy
3 Blue easy
4 OhSINT easy
5 Basic Pentesting easy
6 Vulnversity easy
7 Simple CTF easy
8 Kenobi easy
9 Steel Mountain easy
10 Agent Sudo easy
11 LazyAdmin easy
12 Introductory Networking easy
13 Hydra easy
14 Common Linux Privesc easy
15 Network Services easy
16 Introductory Researching easy
17 What the Shell? easy
18 Hashing - Crypto 101 medium
19 Linux PrivEsc medium
20 Upload Vulnerabilities easy
21 Encryption - Crypto 101 medium
22 Bounty Hacker easy
23 OWASP Juice Shop easy
24 Overpass easy
25 Network Services 2 easy
26 RootMe easy
27 Tutorial easy
28 MITRE medium
29 Starting Out In Cyber Sec easy
30 Nmap easy
31 John the Ripper: The Basics easy
32 Linux Fundamentals Part 1 info
33 Linux Fundamentals Part 2 info
34 How Websites Work easy
35 Linux Fundamentals Part 3 info
36 Putting it all together easy
37 DNS in Detail easy
38 HTTP in Detail easy
39 Windows Fundamentals 1 info
40 Windows Fundamentals 2 info
41 What is Networking? info
42 Intro to LAN info
43 OSI Model info
44 Packets & Frames info
45 Extending Your Network info
46 Learning Cyber Security easy
47 Windows Fundamentals 3 info
48 Linux Privilege Escalation medium
49 Walking An Application easy
50 Pentesting Fundamentals easy
51 Principles of Security info
52 Metasploit: Exploitation easy
53 Content Discovery easy
54 Subdomain Enumeration easy
55 Authentication Bypass easy
56 Junior Security Analyst Intro easy
57 Passive Reconnaissance easy
58 Active Reconnaissance easy
59 Nmap Live Host Discovery medium
60 Nmap Basic Port Scans easy
61 Nmap Advanced Port Scans medium
62 Metasploit: Introduction easy
63 IDOR easy
64 Vulnerabilities 101 easy
65 Metasploit: Meterpreter easy
66 Intro to SSRF easy
67 Pyramid Of Pain easy
68 Intro to Cross-site Scripting easy
69 Nmap Post Port Scans medium
70 Cyber Kill Chain easy
71 Diamond Model easy
72 Vulnerability Capstone easy
73 Exploit Vulnerabilities easy
74 Protocols and Servers easy
75 SQL Injection medium
76 Command Injection easy
77 Net Sec Challenge easy
78 File Inclusion medium
79 Protocols and Servers 2 medium
80 Intro to Digital Forensics easy
81 Introduction to DevSecOps medium
82 Operating System Security easy
83 Lo-Fi easy
84 Network Security easy
85 Web Application Security easy
86 Unified Kill Chain easy
87 SSDLC medium
88 Security Operations easy
89 Careers in Cyber info
90 Windows Privilege Escalation medium
91 Wireshark: The Basics easy
92 Intro to Cyber Threat Intel easy
93 Introduction to SIEM easy
94 Active Directory Basics easy
95 Microsoft Windows Hardening easy
96 Security Principles easy
97 Secure Network Architecture medium
98 Active Directory Hardening medium
99 Introduction to Cryptography medium
100 Network Security Protocols medium
101 OWASP API Security Top 10 - 2 medium
102 OWASP API Security Top 10 - 1 medium
103 Intro to Cloud Security easy
104 Linux System Hardening medium
105 Virtualization and Containers easy
106 Vulnerability Management medium
107 DAST medium
108 Weaponizing Vulnerabilities medium
109 Identity and Access Management easy
110 Network Device Hardening medium
111 Threat Modelling medium
112 Governance & Regulation easy
113 Mother's Secret easy
114 Security Engineer Intro easy
115 SAST medium
116 Risk Management easy
117 Logging for Accountability easy
118 Traverse easy
119 Auditing and Monitoring easy
120 Intro to IR and IM easy
121 Becoming a First Responder info
122 Cyber Crisis Management easy
123 W1seGuy easy
124 Burp Suite: The Basics info
125 Burp Suite: Repeater info
126 Burp Suite: Intruder medium
127 Burp Suite: Other Modules easy
128 Burp Suite: Extensions easy
129 Eviction easy
130 Summit easy
131 Light easy
132 HTTP Request Smuggling easy
133 SSRF medium
134 The Sticker Shop easy
135 File Inclusion, Path Traversal medium
136 CSRF medium
137 XSS easy
138 CORS & SOP easy
139 Prototype Pollution medium
140 Snyk Open Source easy
141 Include medium
142 Moniker Link (CVE-2024-21413) easy
143 Snyk Code easy
144 Race Conditions medium
145 LDAP Injection easy
146 Whats Your Name? medium
147 DOM-Based Attacks easy
148 XXE Injection medium
149 Insecure Deserialisation medium
150 Windows Command Line easy
151 Search Skills easy
152 Server-side Template Injection medium
153 JWT Security easy
154 Nmap: The Basics easy
155 Networking Concepts easy
156 Tcpdump: The Basics easy
157 Networking Essentials easy
158 Networking Core Protocols easy
159 Networking Secure Protocols easy
160 Advanced SQL Injection medium
161 Incident Response Fundamentals easy
162 ORM Injection medium
163 NoSQL Injection easy
164 Logs Fundamentals easy
165 Enumeration & Brute Force easy
166 SOC Fundamentals easy
167 Digital Forensics Fundamentals easy
168 Session Management easy
169 Injectics medium
170 Firewall Fundamentals easy
171 OAuth Vulnerabilities medium
172 IDS Fundamentals easy
173 Multi-Factor Authentication easy
174 Vulnerability Scanner Overview easy
175 Hammer medium
176 CyberChef: The Basics easy
177 Public Key Cryptography Basics easy
178 Cryptography Basics easy
179 Hashing Basics easy
180 CAPA: The Basics easy
181 Windows PowerShell easy
182 FlareVM: Arsenal of Tools easy
183 REMnux: Getting Started easy
184 Linux Shells easy
185 Insecure Randomness easy
186 Gobuster: The Basics easy
187 Training Impact on Teams info
188 SQLMap: The Basics easy
189 Advent of Cyber 2024 easy
190 JavaScript Essentials easy
191 Web Application Basics easy
192 SQL Fundamentals easy
193 Shells Overview easy
194 Breaking Crypto the Simple Way easy
195 Erlang/OTP SSH: CVE-2025-32433 easy
196 Writing Pentest Reports easy
197 Cipher's Secret Message easy
198 Evil-GPT easy
199 Evil-GPT v2 easy
200 Roundcube: CVE-2025-49113 easy
201 Kali Machine easy
202 tmux easy
203 Hacking with PowerShell easy
204 Bebop easy
205 DVWA easy
206 Geolocating Images easy
207 Sudo Security Bypass info
208 Google Dorking easy
209 NIS - Linux Part I easy
210 Python Basics easy
211 Physical Security Intro easy
212 The Hacker Methodology easy
213 Getting Started easy
214 Introduction to Flask easy
215 Cryptography for Dummies easy
216 How to use TryHackMe easy
217 Learn and win prizes info
218 SQLMAP easy
219 Security Awareness info
220 Common Attacks easy
221 Red Team Fundamentals easy
222 Pwnkit: CVE-2021-4034 info
223 Threat Intelligence Tools easy
224 Spring4Shell: CVE-2022-22965 info
225 Intro to Containerisation easy
226 Atlassian CVE-2022-26134 easy
227 Broken Access Control easy
228 The Witch's Cauldron easy
229 Confluence CVE-2023-22515 easy
230 Become a Hacker easy
231 Length Extension Attacks medium
232 Padding Oracles medium
233 Phishing Basics easy
234 Custom Tooling Using Python easy
235 Custom Tooling using Burp hard
236 Tooling via Browser Automation easy
237 SOC L1 Alert Triage easy
238 SOC L1 Alert Reporting easy
239 Cyber Kill Chain medium
240 SOC Workbooks and Lookups easy
241 Attacking ECB Oracles hard
242 Next.js: CVE-2025-29927 easy
243 SOC Metrics and Objectives easy
244 The Building Blocks of AI easy
245 CAPTCHApocalypse medium
246 AI Forensics medium
247 Extract hard
248 AD: BadSuccessor medium
249 Sequence medium
250 ContAInment medium
251 Chaining Vulnerabilities easy
252 Voyage medium
253 Humans as Attack Vectors easy
254 Systems as Attack Vectors easy
255 SOC Role in Blue Team easy
256 Web Security Essentials easy
257 Introduction to Wordlists easy
258 Hack2Win: How you can grab extra tickets info
259 Introduction to EDR easy
260 Input Manipulation & Prompt Injection easy
261 Data Integrity & Model Poisoning medium
262 LLM Output Handling and Privacy Risks easy
263 IDOR - Santa’s Little IDOR medium
264 Obfuscation - The Egg Shell File medium
265 XSS - Merry XSSMas easy
266 Passwords - A Cracking Christmas easy
267 SOC Alert Triaging - Tinsel Triage medium
268 Splunk Basics - Did you SIEM? medium
269 Phishing - Merry Clickmas easy
270 Prompt Injection - Sched-yule conflict easy
271 Linux CLI - Shells Bells easy
272 YARA Rules - YARA mean one! medium
273 Forensics - Registry Furensics medium
274 Exploitation with cURL - Hoperation Eggsploit easy
275 ICS/Modbus - Claus for Concern medium
276 Race Conditions - Toy to The World easy
277 Network Discovery - Scan-ta Clause easy
278 Containers - DoorDasher's Demise medium
279 CyberChef - Hoperation Save McSkidy medium
280 Phishing - Phishmas Greetings medium
281 AI in Security - old sAInt nick easy
282 Malware Analysis - Malhare.exe easy
283 C2 Detection - Command & Carol medium
284 AWS Security - S3cret Santa easy
285 Malware Analysis - Egg-xecutable medium
286 Web Attack Forensics - Drone Alone medium
287 Cloud Security Pitfalls easy
288 Juicy medium
289 Advent of Cyber Prep Track easy
290 OWASP Top 10 2025: IAAA Failures easy
291 OWASP Top 10 2025: Application Design Flaws easy
292 OWASP Top 10 2025: Insecure Data Handling easy
293 Django: CVE-2025-64459 easy
294 BankGPT easy
295 HealthGPT easy
296 React2Shell: CVE-2025-55182 easy
297 Virtualisation Basics easy
298 Operating Systems: Introduction easy
299 Linux CLI Basics easy
300 Data Representation easy
301 Data Encoding easy
302 JavaScript: Simple Demo medium
303 Python: Simple Demo easy
304 LLM Security medium
305 Windows Basics easy
306 Cloud Computing Fundamentals easy
307 Windows CLI Basics easy
308 The CIA Triad easy
309 Database SQL Basics easy
310 Recruit medium
311 Cryptography Concepts easy
312 Client-Server Basics easy
313 Understanding Vulnerability Databases easy
314 Become a Hacker easy
315 Become a Defender easy
316 n8n: CVE-2025-68613 easy
317 Offensive Security Intro easy
318 Inside a Computer System easy
319 GeoServer: CVE-2025-58360 medium
320 Support medium
321 Computer Types easy
322 Dive Into Pentesting easy
323 API Pentesting easy
324 Prompt Engineering easy
325 Checkmate easy
326 AI Models & Data medium
327 Walking An Application easy
328 Defensive Security Intro info
329 AI Threat Modelling medium
330 Securing AI Systems medium
331 CSRF Introduction easy
332 AI System Reconnaissance medium
333 Basic Vulnerability Identification Techniques easy
334 Penetration Testing Frameworks easy
335 Guided Pentest: Infrastructure easy
336 XSS Introduction medium
337 SQL Injection Introduction easy
338 Vulnerability Scanning Tools medium
339 Password Cracking easy
340 Guided Pentest: Web easy
341 Web Server Attacks - I medium
342 AI Threat Modelling Assessment easy
343 AI Security Path Ticketing Event info
344 Web Server Attacks - II medium
345 Broken Authentication easy
346 Modern Web Stacks easy
347 Content Discovery easy
348 CVE-2026-46300: Fragnesia easy
349 CVE-2026-42945: Nginx Rift easy
350 NoScope: Finding RCE medium
351 The Concierge Knows Too Much easy
352 Room 404 easy
353 Complimentary easy
354 Packed Light easy
355 Beach Bar easy
356 Overheard at Breakfast easy
357 Do Not Disturb medium
358 Towel on the Sunbed medium
359 CryptoCabana medium
360 The Hollow Shell medium
361 Infinity Pool medium
362 After Hours medium
363 The Guestbook medium
364 Management Wants a Word hard
Certificates (124)

OSS OopsSec Store badge

Pinned Loading

  1. oss-oopssec-store oss-oopssec-store Public

    Security training for the apps you actually ship. Open your browser and start hacking.

    TypeScript 50 56

  2. OWASP/www-community OWASP/www-community Public

    OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

    HTML 1.4k 853

  3. ThePorgs/Exegol ThePorgs/Exegol Public

    Fully featured and community-driven hacking environment

    Python 3.1k 288

  4. OWASP/OCSD OWASP/OCSD Public

    OWASP Certified Secure-Software Developer

    42 16

  5. nilbuild/developer-roadmap nilbuild/developer-roadmap Public

    Interactive roadmaps, guides and other educational content to help developers grow in their careers.

    TypeScript 369k 45k

  6. OWASP/www-project-vulnerable-web-applications-directory OWASP/www-project-vulnerable-web-applications-directory Public

    The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.

    HTML 94 52