Stars
Preparation guide for Offensive Security's PEN-300 course and OSEP certification exam
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.
Create tar/zip archives that can exploit directory traversal vulnerabilities
OWASP Web Recon & Directory Discovery Platform
ๆๅ ณburpsuite็ๆไปถ(้ๅๅบ),ๆ็ซ ไปฅๅไฝฟ็จๆๅทง็ๆถ้(ๆญค้กน็ฎไธๅๆไพburpsuite็ ด่งฃๆไปถ,ๅฆ้่ฆ่ฏทๅจๅๅฎขmrxn.netไธ่ฝฝ)---Collection of burpsuite plugins (non-stores), articles and tips for using Burpsuite, no crack version file
Burp extension to test for directory traversal attacks in insecure file uploads
Burp extension to detect alias traversal via NGINX misconfiguration at scale.
BurpSuite's payload-generation extension aiming at applying fuzzed test-cases depending on the type of payload (integer, string, path; JSON; XML; GWT; binary) and following encoding-scheme applied โฆ
pFuzz helps us to bypass web application firewall by using different methods at the same time.
A lightweight, portable, and modular tool for Linux enumeration and privilege escalation.
Automated client-side template injection (sandbox escape/bypass) detection for AngularJS v1.x.
opf / rails-angular-xss
Forked from jwhiting/angular_xssPatches rails_xss and Haml so AngularJS interpolations are auto-escaped in unsafe strings.
A website documentation for how to exploit Angular's sandbox through XSS (Cross-Site Scripting)
A blind XSS detection and XSS data capture framework
Vue: Avoid to XSS on decorating for user input.
Cross-Site Scripting(XSS) in Bootstrap-Vue-v4
This script grab public report from hacker one and make some folders with poc videos
Kubernetes security notes and best practices
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
A True Instrumentable Binary Emulation Framework
Collection of VBA macro published in our twitter / blog
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground ๐
A collection of awesome one-liner scripts especially for bug bounty tips.
๐ A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
A python based blind SQL injection exploitation script
A simple python script that exploits blind SQL Injections. Useful for PoCs.