Skip to content
View magma2's full-sized avatar

Block or report magma2

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Preparation guide for Offensive Security's PEN-300 course and OSEP certification exam

252 57 Updated Feb 13, 2021

Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.

Python 1,459 266 Updated Jul 9, 2026

Create tar/zip archives that can exploit directory traversal vulnerabilities

Python 1,055 187 Updated Jun 3, 2021

OWASP Web Recon & Directory Discovery Platform

Python 996 188 Updated Aug 10, 2026

ๆœ‰ๅ…ณburpsuite็š„ๆ’ไปถ(้žๅ•†ๅบ—),ๆ–‡็ซ ไปฅๅŠไฝฟ็”จๆŠ€ๅทง็š„ๆ”ถ้›†(ๆญค้กน็›ฎไธๅ†ๆไพ›burpsuite็ ด่งฃๆ–‡ไปถ,ๅฆ‚้œ€่ฆ่ฏทๅœจๅšๅฎขmrxn.netไธ‹่ฝฝ)---Collection of burpsuite plugins (non-stores), articles and tips for using Burpsuite, no crack version file

HTML 3,957 711 Updated Aug 8, 2026

Burp extension to test for directory traversal attacks in insecure file uploads

Ruby 5 6 Updated Aug 2, 2017

Burp extension to detect alias traversal via NGINX misconfiguration at scale.

Python 266 37 Updated Nov 18, 2021

BurpSuite's payload-generation extension aiming at applying fuzzed test-cases depending on the type of payload (integer, string, path; JSON; XML; GWT; binary) and following encoding-scheme applied โ€ฆ

Python 41 15 Updated Mar 15, 2021

pFuzz helps us to bypass web application firewall by using different methods at the same time.

Python 161 31 Updated Jan 9, 2021

A lightweight, portable, and modular tool for Linux enumeration and privilege escalation.

Shell 295 45 Updated Jan 5, 2026

Automated client-side template injection (sandbox escape/bypass) detection for AngularJS v1.x.

Python 326 94 Updated Oct 20, 2021

Patches rails_xss and Haml so AngularJS interpolations are auto-escaped in unsafe strings.

Ruby 2 7 Updated Jun 5, 2022

demo xss vulnerability in react v13

JavaScript 9 Updated Jul 28, 2026

An insecure application

JavaScript 5 1 Updated Jan 31, 2018

A website documentation for how to exploit Angular's sandbox through XSS (Cross-Site Scripting)

HTML 1 Updated Dec 29, 2018

A blind XSS detection and XSS data capture framework

Python 176 29 Updated Dec 6, 2025

Vue: Avoid to XSS on decorating for user input.

Vue 2 Updated Nov 2, 2019

Cross-Site Scripting(XSS) in Bootstrap-Vue-v4

JavaScript 1 Updated Apr 23, 2018

This script grab public report from hacker one and make some folders with poc videos

Shell 924 222 Updated Oct 10, 2025

Kubernetes security notes and best practices

Shell 730 76 Updated Apr 15, 2022

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

XSLT 8,731 1,161 Updated Jul 31, 2026

A True Instrumentable Binary Emulation Framework

Python 6,051 796 Updated Jul 22, 2026

Collection of VBA macro published in our twitter / blog

VBA 156 17 Updated Sep 5, 2022

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground ๐Ÿš€

HTML 5,742 1,035 Updated Apr 16, 2026

A collection of awesome one-liner scripts especially for bug bounty tips.

3,177 630 Updated Jul 29, 2024

๐Ÿ” A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

C++ 54,428 2,442 Updated Aug 11, 2026

A python based blind SQL injection exploitation script

Python 144 52 Updated Jan 26, 2020

A simple python script that exploits blind SQL Injections. Useful for PoCs.

Python 27 15 Updated Jul 31, 2013
Next