HowToLogin - HTLogin is authentication security scanner for login forms, APIs, and SPAs. With bypass testing, enumeration, rate-limit checks, and evidence-based detection.
-
Updated
Sep 30, 2026 - Python
HowToLogin - HTLogin is authentication security scanner for login forms, APIs, and SPAs. With bypass testing, enumeration, rate-limit checks, and evidence-based detection.
Local PHP/MySQL e-wallet application combined with a hands-on cybersecurity demo lab. Implements user/admin auth, balances, transfers, CSRF protection, session timeouts, login lockout, and hashing. Includes a toggleable Vulnerable/Secure lab to demonstrate XSS and session hijacking with real code and mitigations.
A hands-on simulation of attacking a vulnerable login page using Python. This repo includes a Flask-based vulnerable login page and Python scripts to exploit weaknesses in regex validation and brute-force login attempts. Perfect for learning web penetration testing basics and ethical hacking techniques.
Historical social-engineering research project exploring phishing awareness and authentication security.
This project demonstrates SSH authentication log analysis using Splunk SIEM to detect malicious activity such as brute-force attacks, unauthorized access attempts, and suspicious SSH behavior. It simulates real-world SOC analyst workflows, including log ingestion, SPL queries, dashboards, and alerting.
JWT security audit CLI — detects alg:none attacks, cracks weak secrets via dictionary, tests expiry abuse, validates audience/issuer claims. Exit codes integrate into CI gates. Python + PyJWT.
A Bash-based password security toolkit that checks strength against common passwords, provides color-coded scoring & feedback, and logs results for security auditing.
A full-stack defensive cybersecurity tool that analyzes password strength, detects common and predictable weaknesses, provides security suggestions, generates strong passwords, and visualizes aggregate security analytics.
Password security assessment and credential attack simulation toolkit
🎮 A full-stack multiplayer Pong game reimagined with modern web tech: Fastify, TypeScript, TailwindCSS, SQLite, Docker, OAuth2, JWT, AI opponent, and Blockchain score storage. Built as the final core project at 42 Beirut.
Investigated suspicious Windows and Linux activity by correlating account manipulation, privilege escalation, SSH authentication, potential lateral movement, and file integrity events. Built a timeline using Wazuh telemetry, identified key indicators, documented evidence, and developed response actions and security recommendations.
🔒 Login attempt control & rate-limiting system with independent per-user tracking, lockout timers, and audit logging.
Defensive password security tool featuring real-time strength analysis, security suggestions, secure password generation, policy checking, analytics, and educational hashing.
Identity and credential security toolkit for assessing authentication, credentials, identity systems, and access-control weaknesses.
SecureAura is a Dockerized microservices framework that defends authentication endpoints from timing-based side-channel attacks.
Python-based SOC tool to detect brute force attacks using failed login patterns, time-based analysis, and risk scoring.
Password Strength Analyzer with brute force simulation (educational). Evaluates password complexity, detects weak/common passwords, and provides improvement recommendations. Practical project focused on password security awareness and defensive security practices.
Cybersecurity & cloud security portfolio featuring SOC investigations, AWS security projects, vulnerability analysis, Linux, and Python.
To associate your repository with the authentication-security topic, visit your repo's landing page and select "manage topics."