Highlights
Stars
CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting) vulnerabilities on sites where injections are blocke…
GQLSpection - parses GraphQL introspection schema and generates possible queries
Automated & Manual Wordlists provided by Assetnote
Burp Plugin to Bypass WAFs through the insertion of Junk Data
Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit
A cryptographically verifiable code review system for the cargo (Rust) package manager.
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
A fast, simple, recursive content discovery tool written in Rust.
Web Application Security Automation Framework which recons the target for various assets to maximize the attack surface for security professionals & bug-hunters
Merge objects & other types recursively. A simple & small integration.
Proof of Concept code for CVE-2015-0345 (APSB15-07)
A Puppeteer bridge for PHP, supporting the entire API.
A collection of browser-based side channel attack vectors.
awesome list of browser exploitation tutorials
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
Automatically exported from code.google.com/p/domxsswiki
A list of interesting payloads, tips and tricks for bug bounty hunters.
Documentation for Essential Node.js Security
A book series (2 published editions) on the JS language.
Collection of the cheat sheets useful for pentesting
Pwnable|Web Security|Cryptography CTF-style challenges
🍭 Wow, such a lovely HTML5 danmaku video player