Skip to content
View terjanq's full-sized avatar

Organizations

@xsleaks @googlers @justcatthefish @CTF-Organizers

Block or report terjanq

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
38 results for source starred repositories
Clear filter

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

JavaScript 16,194 815 Updated Nov 10, 2025

Web path scanner

Python 13,632 2,405 Updated Oct 20, 2025

Some setup scripts for security research tools.

Shell 9,176 1,919 Updated Oct 29, 2025

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Python 3,233 397 Updated Apr 18, 2023

The cheat sheet about Java Deserialization vulnerabilities

3,147 602 Updated May 26, 2023

OWASP CRS (Official Repository)

Python 2,852 424 Updated Nov 11, 2025

HTTPLeaks - All possible ways, a website can leak HTTP requests

HTML 2,068 206 Updated Oct 23, 2024

Reverse proxies cheatsheet

Python 1,854 218 Updated Nov 4, 2023

Prototype Pollution and useful Script Gadgets

1,539 215 Updated Jan 27, 2024

List of XSS Vectors/Payloads

1,339 269 Updated Jan 2, 2025

A generator of weird files (binary polyglots, near polyglots, polymocks...)

Python 1,251 82 Updated Dec 22, 2024

A collection of browser-based side channel attack vectors.

757 51 Updated Mar 19, 2024

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

PHP 731 110 Updated May 6, 2024

Content-Type Research

641 66 Updated Jun 29, 2025

Client Side Prototype Pollution Scanner

JavaScript 522 63 Updated Sep 17, 2022

Automated security reporting from markdown templates (HackerOne and Bugcrowd are currently the platforms supported)

Shell 459 68 Updated May 10, 2019

A tool to perform Sequential Import Chaining

Rust 282 14 Updated Sep 11, 2019

XS-Leaks Wiki

HTML 169 53 Updated May 29, 2025

ctf exploit codes or writeups

Python 160 16 Updated Dec 9, 2024

Collection of my capture-the-flag web challenge in any levels

PHP 116 34 Updated Jan 19, 2023

CTF write-ups

Python 99 25 Updated Sep 12, 2025

Searcher for cross-site leaks (XS-Leaks)

JavaScript 82 5 Updated Dec 27, 2022

Same Origin XSS challenge

HTML 64 5 Updated Apr 7, 2022

justCTF 2019 challenges sources

SystemVerilog 40 6 Updated Jun 9, 2021

CTF Writeups

Python 39 6 Updated Sep 23, 2018

Challenge repository for the watevrCTF 2019 CTF competition

C 37 10 Updated Jun 6, 2022

CTF writeups

JavaScript 30 7 Updated May 27, 2022

Legend Agar.io Mod

JavaScript 28 128 Updated Nov 10, 2025
Next