Stars
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
Some setup scripts for security research tools.
This tool generates gopher link for exploiting SSRF and gaining RCE in various servers
The cheat sheet about Java Deserialization vulnerabilities
HTTPLeaks - All possible ways, a website can leak HTTP requests
Prototype Pollution and useful Script Gadgets
A generator of weird files (binary polyglots, near polyglots, polymocks...)
A collection of browser-based side channel attack vectors.
A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.
Automated security reporting from markdown templates (HackerOne and Bugcrowd are currently the platforms supported)
Collection of my capture-the-flag web challenge in any levels
Implementation of attacks on cryptosystems
justCTF 2019 challenges sources
Challenge repository for the watevrCTF 2019 CTF competition