My name is Ivan, or Steph. I do security trainings, researches, and, occasionally, some bug-hunting, pentests, and other security stuff. On top of that buildding tools for recon, cracking, and web testing, then open-source them. Spoke at many conferences including BlackHat US/Europe, Hacktivity, GreHack, CONFidence, One-Conference, and others.
Find me: @w34kp455
- weakpass.com - wordlists and hash-cracking tooling
- shrewdeye.app - recon and bug-hunting automation
- appsec.study - a free e-learning platform for application security
- boxcutter - every web-testing tool in one container, one CLI, one JSON output. subfinder, httpx, nuclei, ZAP, sqlmap and more, plus LLM agents that drive them.
- lockpick.fun - a browser lockpicking simulator with real pin mechanics: binding order, security pins, false sets.
- crack-js - hashcat-format hash cracking in pure JavaScript. Powers the cracking on weakpass.com.
- low-hanging-vulns - live monitoring of critical and high web bugs



