Skip to content
View kOaDT's full-sized avatar
🍉
🍉
  • France

Block or report kOaDT

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kOaDT/README.md

AppSec & Web Developer

Header

TryHackMe   Root-Me


Vulnerabilities Reported (2)
Advisory CVE Severity Date Summary
GHSA-g747-7v24-2w4v - Medium 2026-08-21 OAuth2 state parameter is not validated on callback, allowing authorization code injection
GHSA-qrx8-9hc6-jvqg CVE-2026-32255 High (8.6) 2026-03-18 Unauthenticated SSRF in attachment download endpoint
CVE Proof of Concepts (3)
CVE Description 🍴 👁️ 📥
CVE-2025-55182 This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React Server Components, also known as React2Shell. 15 3 5747 1735
CVE-2025-29927 This repository contains a POC and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware. 8 3 2656 998
CVE-2026-32255 This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an open-source project management tool. 2 - 1064 371
Projects (5)
Project Description 🍴 👁️ 📥
oss-oopssec-store Security training for the apps you actually ship. Open your browser and start hacking. 44 52 6871 54916
cyber-bot Threat intelligence platform: RSS aggregation, NVD CVE tracking, ENISA EUVD, databreaches, ... 7 1 261537 2201
hate-crimes-map This project aims to visualize hate crime data to bring visibility to crimes that are often invisible or normalized by society. 3 - 158 594
awesome-pentest-tools Open-source offensive security tools, plus a vendor-agnostic AI agent that runs authorized pentest engagements using only tools from this list. 3 2 46 261
crack-hash A fast, multi-threaded hash cracking tool written in Rust. This tool performs dictionary attacks against hashed passwords. 2 - 82 63
OSS Contributions (21)
Repository Description 🍴
kanbn/kan The open source Trello alternative. 5627 468
ThePorgs/Exegol Fully featured and community-driven hacking environment 3085 286
beelzebub-labs/beelzebub A secure low code deception runtime framework, leveraging AI for System Virtualization. 2172 208
OWASP/www-community OWASP Community Pages are a place where OWASP can accept community contributions for security-related content. 1409 844
OWASP/www-project-vulnerable-web-applications-directory The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available. 94 52
nilbuild/developer-roadmap Interactive roadmaps, guides and other educational content to help developers grow in their careers. 367006 44931
mermaid-js/mermaid Generation of diagrams like flowcharts or sequence diagrams from text in a similar manner as markdown 90216 9252
usebruno/bruno Opensource IDE For Exploring and Testing API's (lightweight alternative to Postman/Insomnia) 46918 2871
enaqx/awesome-pentest A collection of awesome penetration testing resources, tools and other shiny things 27185 4946
qazbnm456/awesome-web-security 🐶 A curated list of Web Security materials and resources. 13786 1819
infoslack/awesome-web-hacking A list of web application security 7265 1361
satnaing/astro-paper A minimal, accessible and SEO-friendly Astro blog theme. 5041 1096
husnainfareed/awesome-ethical-hacking-resources 😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing. 3764 561
lingdojo/kana-dojo Aesthetic, minimalist platform for learning Japanese inspired by Duolingo and Monkeytype, built with Next.js and sponsored by Vercel. Beginner-friendly with plenty of good first issues - all contributions are welcome! 3368 3275
fabionoth/awesome-cyber-security A collection of awesome software, libraries, documents, books, resources and cools stuffs about security. 1944 268
vavkamil/awesome-vulnerable-apps Awesome Vulnerable Applications 1482 227
kaiiyer/awesome-vulnerable A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB. 1391 228
okhosting/awesome-cyber-security A curated list of cyber security resources and tools. 737 122
Grafikart/Grafikart.fr Dépôt pour la nouvelle version de Grafikart.fr 700 191
noraj/rawsec-cybersecurity-inventory An inventory of tools and resources about CyberSecurity that aims to help people to find everything related to CyberSecurity. 346 75
secnotes/awesome-cybersecurity A collection of awesome github repositories about security 82 11
Publications (1)
Title Platform Category Date
MCP Tool Poisoning OWASP article 2026-03-26
Github Metrics

TryHackMe Stats
Global Rank Top Streak
#12849 1% 760 days
TryHackMe Badges (50)
  • Networking NerdCompleting the 'Network Fundamentals' module
  • 7 Day StreakAchieving a 7 day hacking streak
  • WebbedUnderstands how the world wide web works
  • World Wide WebCompleting the 'How The Web Works' module
  • cat linux.txtBeing competent in Linux
  • 30 Day StreakHacking for 30 days solid
  • OWASP Top 10Understanding every OWASP vulnerability
  • Hash CrackerCracking all those hashes
  • MetasploitableContains the knowledge to use Metasploit
  • BlueHacking into Windows via EternalBlue
  • Cyber ReadyUnderstanding impact of training on teams
  • Sword ApprenticeCompleting the SQLMap room
  • Shield ApprenticeCompleting the FlareVM room
  • 90 Day StreakHacking for 90 days in a row
  • Linux PrivEscMastering Linux Privilege Escalation
  • Pentesting PrinciplesCompleting the 'Introduction to Pentesting' module
  • Intro to Web HackingCompleting the 'Introduction to Web Hacking' module
  • Advent of Cyber 2024Completing Advent of Cyber 2024!
  • Burp'edCompleting the Burp Suite module
  • 180 Day StreakHacking for 180 days in a row
  • Authentication StrikerUsed the Hammer to bypass authentication
  • SQL SlayerConquered Advanced SQL Injection
  • System SnifferCompleted the File Path traversal room
  • OhSINTCompleting the OhSINT room
  • Client-Side ChampSuccessfully exploited client-side vulnerabilities
  • Introduction to Security EngineeringCompleted the Security Engineer Intro room!
  • Calculated Risk — _Completed the Risk Management room! _
  • 3 Day StreakAchieving a 3 day hacking streak
  • Network and System SecurityFinished the Auditing and Monitoring room!
  • Software Security — _Completed the OWASP API Security Top 10 rooms! _
  • 365 Day StreakHacking for 365 days in a row
  • The Course AwakensFinishing the first room in the DevSecOps path!
  • Just have to deal with it — _Successfully managed a cyber crisis! _
  • Raffle RoyaltyParticipating in Hack2Win 2025!
  • /opt/m0th3rFinishing Mother’s Secret!
  • Skilled NavigatorFinishing the Eviction challenge!
  • First Step into SOCExplored emerging threats and SOC response
  • SOC ApprenticeExplored how a SOC team operates from inside
  • First alert closedClosing your first alert
  • First scenario completedCompleting your first scenario
  • 100% true positive rateAchieving 100% true positive rate in a scenario
  • 500 Day StreakHacking for 500 days in a row
  • Tooling SpecialistAdept in creating custom offensive tooling
  • Advent of Cyber 2025Completing Advent of Cyber 2025!
  • Model CompromiseCompleted the LLM Attacks Module
  • Session HeldCompleting 4 weekly missions in a row!
  • Security AwarenessCompleting the cyber security awareness module
  • Adversarial Defence OpsTrained to Defend, Built to Learn.
  • AI OdysseyTaking part in the AI Odyssey event!
  • 750 Day StreakHacking for 750 days in a row
TryHackMe Completed Rooms (352)
# Room Difficulty
1 Crack the hash easy
2 Pickle Rick easy
3 Blue easy
4 OhSINT easy
5 Basic Pentesting easy
6 Vulnversity easy
7 Simple CTF easy
8 Kenobi easy
9 Steel Mountain easy
10 Agent Sudo easy
11 LazyAdmin easy
12 Introductory Networking easy
13 Hydra easy
14 Common Linux Privesc easy
15 Network Services easy
16 Introductory Researching easy
17 What the Shell? easy
18 Hashing - Crypto 101 medium
19 Linux PrivEsc medium
20 Upload Vulnerabilities easy
21 Encryption - Crypto 101 medium
22 Bounty Hacker easy
23 OWASP Juice Shop easy
24 Overpass easy
25 Network Services 2 easy
26 RootMe easy
27 Tutorial easy
28 MITRE medium
29 Starting Out In Cyber Sec easy
30 Nmap easy
31 John the Ripper: The Basics easy
32 Linux Fundamentals Part 1 info
33 Linux Fundamentals Part 2 info
34 How Websites Work easy
35 Linux Fundamentals Part 3 info
36 Putting it all together easy
37 DNS in Detail easy
38 HTTP in Detail easy
39 Windows Fundamentals 1 info
40 Windows Fundamentals 2 info
41 What is Networking? info
42 Intro to LAN info
43 OSI Model info
44 Packets & Frames info
45 Extending Your Network info
46 Learning Cyber Security easy
47 Windows Fundamentals 3 info
48 Linux Privilege Escalation medium
49 Walking An Application easy
50 Pentesting Fundamentals easy
51 Principles of Security info
52 Metasploit: Exploitation easy
53 Content Discovery easy
54 Subdomain Enumeration easy
55 Authentication Bypass easy
56 Junior Security Analyst Intro easy
57 Passive Reconnaissance easy
58 Active Reconnaissance easy
59 Nmap Live Host Discovery medium
60 Nmap Basic Port Scans easy
61 Nmap Advanced Port Scans medium
62 Metasploit: Introduction easy
63 IDOR easy
64 Vulnerabilities 101 easy
65 Metasploit: Meterpreter easy
66 Intro to SSRF easy
67 Pyramid Of Pain easy
68 Intro to Cross-site Scripting easy
69 Nmap Post Port Scans medium
70 Cyber Kill Chain easy
71 Diamond Model easy
72 Vulnerability Capstone easy
73 Exploit Vulnerabilities easy
74 Protocols and Servers easy
75 SQL Injection medium
76 Command Injection easy
77 Net Sec Challenge easy
78 File Inclusion medium
79 Protocols and Servers 2 medium
80 Intro to Digital Forensics easy
81 Introduction to DevSecOps medium
82 Operating System Security easy
83 Lo-Fi easy
84 Network Security easy
85 Web Application Security easy
86 Unified Kill Chain easy
87 SSDLC medium
88 Security Operations easy
89 Careers in Cyber info
90 Windows Privilege Escalation medium
91 Wireshark: The Basics easy
92 Intro to Cyber Threat Intel easy
93 Introduction to SIEM easy
94 Active Directory Basics easy
95 Microsoft Windows Hardening easy
96 Security Principles easy
97 Secure Network Architecture medium
98 Active Directory Hardening medium
99 Introduction to Cryptography medium
100 Network Security Protocols medium
101 OWASP API Security Top 10 - 2 medium
102 OWASP API Security Top 10 - 1 medium
103 Intro to Cloud Security easy
104 Linux System Hardening medium
105 Virtualization and Containers easy
106 Vulnerability Management medium
107 DAST medium
108 Weaponizing Vulnerabilities medium
109 Identity and Access Management easy
110 Network Device Hardening medium
111 Threat Modelling medium
112 Governance & Regulation easy
113 Mother's Secret easy
114 Security Engineer Intro easy
115 SAST medium
116 Risk Management easy
117 Logging for Accountability easy
118 Traverse easy
119 Auditing and Monitoring easy
120 Intro to IR and IM easy
121 Becoming a First Responder info
122 Cyber Crisis Management easy
123 W1seGuy easy
124 Burp Suite: The Basics info
125 Burp Suite: Repeater info
126 Burp Suite: Intruder medium
127 Burp Suite: Other Modules easy
128 Burp Suite: Extensions easy
129 Eviction easy
130 Summit easy
131 Light easy
132 HTTP Request Smuggling easy
133 SSRF medium
134 The Sticker Shop easy
135 File Inclusion, Path Traversal medium
136 CSRF medium
137 XSS easy
138 CORS & SOP easy
139 Prototype Pollution medium
140 Snyk Open Source easy
141 Include medium
142 Moniker Link (CVE-2024-21413) easy
143 Snyk Code easy
144 Race Conditions medium
145 LDAP Injection easy
146 Whats Your Name? medium
147 DOM-Based Attacks easy
148 XXE Injection medium
149 Insecure Deserialisation medium
150 Windows Command Line easy
151 Search Skills easy
152 Server-side Template Injection medium
153 JWT Security easy
154 Nmap: The Basics easy
155 Networking Concepts easy
156 Tcpdump: The Basics easy
157 Networking Essentials easy
158 Networking Core Protocols easy
159 Networking Secure Protocols easy
160 Advanced SQL Injection medium
161 Incident Response Fundamentals easy
162 ORM Injection medium
163 NoSQL Injection easy
164 Logs Fundamentals easy
165 Enumeration & Brute Force easy
166 SOC Fundamentals easy
167 Digital Forensics Fundamentals easy
168 Session Management easy
169 Injectics medium
170 Firewall Fundamentals easy
171 OAuth Vulnerabilities medium
172 IDS Fundamentals easy
173 Multi-Factor Authentication easy
174 Vulnerability Scanner Overview easy
175 Hammer medium
176 CyberChef: The Basics easy
177 Public Key Cryptography Basics easy
178 Cryptography Basics easy
179 Hashing Basics easy
180 CAPA: The Basics easy
181 Windows PowerShell easy
182 FlareVM: Arsenal of Tools easy
183 REMnux: Getting Started easy
184 Linux Shells easy
185 Insecure Randomness easy
186 Gobuster: The Basics easy
187 Training Impact on Teams info
188 SQLMap: The Basics easy
189 Advent of Cyber 2024 easy
190 JavaScript Essentials easy
191 Web Application Basics easy
192 SQL Fundamentals easy
193 Shells Overview easy
194 Breaking Crypto the Simple Way easy
195 Erlang/OTP SSH: CVE-2025-32433 easy
196 Writing Pentest Reports easy
197 Cipher's Secret Message easy
198 Evil-GPT easy
199 Evil-GPT v2 easy
200 Roundcube: CVE-2025-49113 easy
201 Kali Machine easy
202 tmux easy
203 Hacking with PowerShell easy
204 Bebop easy
205 DVWA easy
206 Geolocating Images easy
207 Sudo Security Bypass info
208 Google Dorking easy
209 NIS - Linux Part I easy
210 Python Basics easy
211 Physical Security Intro easy
212 The Hacker Methodology easy
213 Getting Started easy
214 Introduction to Flask easy
215 Cryptography for Dummies easy
216 How to use TryHackMe easy
217 Learn and win prizes info
218 SQLMAP easy
219 Security Awareness info
220 Common Attacks easy
221 Red Team Fundamentals easy
222 Pwnkit: CVE-2021-4034 info
223 Threat Intelligence Tools easy
224 Spring4Shell: CVE-2022-22965 info
225 Intro to Containerisation easy
226 Atlassian CVE-2022-26134 easy
227 Broken Access Control easy
228 The Witch's Cauldron easy
229 Confluence CVE-2023-22515 easy
230 Become a Hacker easy
231 Length Extension Attacks medium
232 Padding Oracles medium
233 Phishing Basics easy
234 Custom Tooling Using Python easy
235 Custom Tooling using Burp hard
236 Tooling via Browser Automation easy
237 SOC L1 Alert Triage easy
238 SOC L1 Alert Reporting easy
239 Cyber Kill Chain medium
240 SOC Workbooks and Lookups easy
241 Attacking ECB Oracles hard
242 Next.js: CVE-2025-29927 easy
243 SOC Metrics and Objectives easy
244 The Building Blocks of AI easy
245 CAPTCHApocalypse medium
246 AI Forensics medium
247 Extract hard
248 Sequence medium
249 ContAInment medium
250 Chaining Vulnerabilities easy
251 Voyage medium
252 Humans as Attack Vectors easy
253 Systems as Attack Vectors easy
254 SOC Role in Blue Team easy
255 Web Security Essentials easy
256 Hack2Win: How you can grab extra tickets info
257 Introduction to EDR easy
258 Input Manipulation & Prompt Injection easy
259 Data Integrity & Model Poisoning medium
260 LLM Output Handling and Privacy Risks easy
261 IDOR - Santa’s Little IDOR medium
262 Obfuscation - The Egg Shell File medium
263 XSS - Merry XSSMas easy
264 Passwords - A Cracking Christmas easy
265 SOC Alert Triaging - Tinsel Triage medium
266 Splunk Basics - Did you SIEM? medium
267 Phishing - Merry Clickmas easy
268 Prompt Injection - Sched-yule conflict easy
269 Linux CLI - Shells Bells easy
270 YARA Rules - YARA mean one! medium
271 Forensics - Registry Furensics medium
272 Exploitation with cURL - Hoperation Eggsploit easy
273 ICS/Modbus - Claus for Concern medium
274 Race Conditions - Toy to The World easy
275 Network Discovery - Scan-ta Clause easy
276 Containers - DoorDasher's Demise medium
277 CyberChef - Hoperation Save McSkidy medium
278 Phishing - Phishmas Greetings medium
279 AI in Security - old sAInt nick easy
280 Malware Analysis - Malhare.exe easy
281 C2 Detection - Command & Carol medium
282 AWS Security - S3cret Santa easy
283 Malware Analysis - Egg-xecutable medium
284 Web Attack Forensics - Drone Alone medium
285 Cloud Security Pitfalls easy
286 Juicy medium
287 Advent of Cyber Prep Track easy
288 OWASP Top 10 2025: Insecure Data Handling easy
289 Django: CVE-2025-64459 easy
290 BankGPT easy
291 HealthGPT easy
292 React2Shell: CVE-2025-55182 easy
293 Virtualisation Basics easy
294 Operating Systems: Introduction easy
295 Linux CLI Basics easy
296 Data Representation easy
297 Data Encoding easy
298 JavaScript: Simple Demo medium
299 Python: Simple Demo easy
300 LLM Security medium
301 Windows Basics easy
302 Cloud Computing Fundamentals easy
303 Windows CLI Basics easy
304 The CIA Triad easy
305 Database SQL Basics easy
306 Recruit medium
307 Cryptography Concepts easy
308 Client-Server Basics easy
309 Become a Hacker easy
310 Become a Defender easy
311 n8n: CVE-2025-68613 easy
312 Offensive Security Intro easy
313 Inside a Computer System easy
314 GeoServer: CVE-2025-58360 medium
315 Support medium
316 Computer Types easy
317 Dive Into Pentesting easy
318 API Pentesting easy
319 Prompt Engineering easy
320 AI Models & Data medium
321 Walking An Application easy
322 Defensive Security Intro info
323 AI Threat Modelling medium
324 Securing AI Systems medium
325 CSRF Introduction easy
326 AI System Reconnaissance medium
327 Penetration Testing Frameworks easy
328 Guided Pentest: Infrastructure easy
329 XSS Introduction medium
330 SQL Injection Introduction easy
331 Guided Pentest: Web easy
332 Web Server Attacks - I medium
333 AI Threat Modelling Assessment easy
334 AI Security Path Ticketing Event info
335 Web Server Attacks - II medium
336 Broken Authentication easy
337 Modern Web Stacks easy
338 Content Discovery easy
339 The Concierge Knows Too Much easy
340 Room 404 easy
341 Complimentary easy
342 Packed Light easy
343 Beach Bar easy
344 Overheard at Breakfast easy
345 Do Not Disturb medium
346 Towel on the Sunbed medium
347 CryptoCabana medium
348 The Hollow Shell medium
349 Infinity Pool medium
350 After Hours medium
351 The Guestbook medium
352 Management Wants a Word hard
Certificates (124)

OSS OopsSec Store badge

Pinned Loading

  1. oss-oopssec-store oss-oopssec-store Public

    Security training for the apps you actually ship. Open your browser and start hacking.

    TypeScript 44 52

  2. OWASP/www-community OWASP/www-community Public

    OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

    HTML 1.4k 845

  3. ThePorgs/Exegol ThePorgs/Exegol Public

    Fully featured and community-driven hacking environment

    Python 3.1k 286

  4. OWASP/www-project-vulnerable-web-applications-directory OWASP/www-project-vulnerable-web-applications-directory Public

    The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.

    HTML 94 52

  5. nilbuild/developer-roadmap nilbuild/developer-roadmap Public

    Interactive roadmaps, guides and other educational content to help developers grow in their careers.

    TypeScript 367k 44.9k

  6. poc-cve-2025-55182 poc-cve-2025-55182 Public

    This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React Server Components, also known as React2Shell.

    TypeScript 15 3