> dmcdonald.net / tools > ─────────────────────
Tools, Code, & Exploits
offensive tooling and small utilities, mostly released under GPL-3.0. Pre-Cryptic Red work sits under R3n5k1/; the Cryptic Red era under CR-DMcDonald/; new work consolidating under R3n5k1/.
── current ───────────────────────────────────
dellpwn
Recovers and resets Dell (and some related HP) BIOS passwords from an SPI flash dump. Dell stores BIOS passwords XOR-encrypted rather than hashed, and a length mismatch leaks the key, so the password is recovered deterministically from a dump with no brute force (CVE-2026-40639). Joint research with Craig S. Blackie of MDSec. Authorised use only: recovery requires physical access to the device and its flash chip.
IRExitSensors
A collaborative reference collection on infrared exit sensors: the sensor models found on access-controlled doors, their susceptibility to signal patterns, and how to build IR emitters ("torches") to trip them. Less a single tool than a shared knowledge base for hardware hackers and red teamers working on door-sensor bypass. I maintain it, but several others have made significant contributions.
voipire
RTP Bleed exploit for vulnerable Session Border Controllers. Scans for RTP streams and dumps raw audio to file for analysis. Renamed from rtp-red-cap (the original Cryptic Red name). Use with authorisation: the exploit can cause significant disruption on vulnerable SBCs.
── historical ────────────────────────────────
WebLogic 10.3.3 UNC Path Exploit Package
A pre-packaged vulnerable WebLogic 10.3.3 environment plus UNC-path payload batch file, built because the public Node Manager UNC-path RCE was painful to reproduce on engagement. Not a novel vulnerability; this is exploitation tooling for an existing public bug, made to lower the setup cost during testing. Default credentials weblogic / w3bl0g1c.