Skip to content
View h1pmnh's full-sized avatar

Block or report h1pmnh

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Automated web vulnerability scanning with LLM agents

Python 470 64 Updated Jun 18, 2025

A tool to help you intercept encrypted APIs in iOS or Android apps

JavaScript 329 43 Updated Aug 23, 2024

Prompt Injection Primer for Engineers

596 67 Updated Aug 25, 2023

OAuth 2.0 exploitation, attack and research tools.

Python 13 2 Updated Jan 20, 2024

MySQL JDBC Deserialization Payload / MySQL客户端jdbc反序列化漏洞payload

C++ 13 14 Updated Feb 8, 2020

An IIS short filename enumeration tool

Go 1,177 114 Updated Nov 25, 2024

JavaScript-based web UI to decode ad-hoc Protobuf data

JavaScript 663 133 Updated Jun 1, 2026

A simple zero-config tool to make locally trusted development certificates with any names you'd like.

Go 59,086 3,126 Updated Aug 13, 2024

A library for detecting known secrets across many web frameworks

Python 803 81 Updated Jun 14, 2026

A tool to fetch all in scope assets of HackerOne programs for integration in your automation and hacking workflow using HackerOne's hacker API

Go 6 2 Updated Aug 29, 2023

A tool to guess the rest of the shortnames provided by vulnerable IIS instances.

Python 41 7 Updated Aug 12, 2023

Detect and bypass web application firewalls and protection systems

Python 2,901 470 Updated Aug 11, 2024

A copy of Mura when it was still open-source in August 2020

11 19 Updated Aug 12, 2020

MOVEit CVE-2023-34362

Python 138 34 Updated Jun 26, 2023

Automating situational awareness for cloud penetration tests.

Go 2,440 234 Updated May 26, 2026

DNS rebinding toolkit

JavaScript 255 42 Updated May 22, 2023

XSS payloads designed to turn alert(1) into P1

JavaScript 1,398 224 Updated Sep 12, 2023

Unofficial documentation for the great tool Param Miner

186 30 Updated Aug 21, 2022

CVE-2022-21587 POC

Python 15 7 Updated Feb 17, 2023

A community-powered collection of all known bug bounty platforms, vulnerability disclosure platforms, and crowdsourced security platforms currently active on the Internet.

HTML 1,034 206 Updated Jun 13, 2026

Azure Security Resources and Notes

PowerShell 1,755 230 Updated Feb 17, 2026

All my infosec notes I have been building up over the years

338 85 Updated Apr 28, 2026

essential templates for kenzer [DEPRECATED]

Python 119 38 Updated Mar 7, 2023

Need any help bypassing CSP ?

JavaScript 34 4 Updated Nov 13, 2020

pwm

Java 972 261 Updated Jun 23, 2025

Create tar/zip archives that can exploit directory traversal vulnerabilities

Python 1,047 187 Updated Jun 3, 2021

An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!

JavaScript 2,388 418 Updated Mar 7, 2024

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,135 1,317 Updated Mar 10, 2021
Next