Skip to content
View terjanq's full-sized avatar

Organizations

@xsleaks @googlers @justcatthefish @CTF-Organizers

Block or report terjanq

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Searcher for cross-site leaks (XS-Leaks)

JavaScript 82 5 Updated Dec 27, 2022

Automated security reporting from markdown templates (HackerOne and Bugcrowd are currently the platforms supported)

Shell 459 68 Updated May 10, 2019

OWASP CRS (Official Repository)

Python 2,841 422 Updated Nov 4, 2025

Same Origin XSS challenge

HTML 64 5 Updated Apr 7, 2022

XS-Leaks Wiki

HTML 169 52 Updated May 29, 2025

A generator of weird files (binary polyglots, near polyglots, polymocks...)

Python 1,251 82 Updated Dec 22, 2024

Client Side Prototype Pollution Scanner

JavaScript 521 63 Updated Sep 17, 2022

Prototype Pollution and useful Script Gadgets

1,538 215 Updated Jan 27, 2024

Writeups for some CTF challenges. I keep the copy of task files in case you would like to try them yourself.

Python 12 Updated Oct 4, 2021

CTF writeups

JavaScript 30 7 Updated May 27, 2022

Content-Type Research

641 65 Updated Jun 29, 2025

The cheat sheet about Java Deserialization vulnerabilities

3,147 602 Updated May 26, 2023

Reverse proxies cheatsheet

Python 1,854 217 Updated Nov 4, 2023

A JavaScript sandbox using proxies

JavaScript 20 2 Updated Jul 18, 2020

justCTF 2019 challenges sources

SystemVerilog 40 6 Updated Jun 9, 2021

Challenge repository for the watevrCTF 2019 CTF competition

C 37 10 Updated Jun 6, 2022

ctf exploit codes or writeups

Python 160 16 Updated Dec 9, 2024

Implementation of attacks on cryptosystems

Python 76 14 Updated Jul 29, 2025

HTTPLeaks - All possible ways, a website can leak HTTP requests

HTML 2,067 205 Updated Oct 23, 2024

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

JavaScript 16,168 810 Updated Oct 21, 2025

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

PHP 731 110 Updated May 6, 2024

List of XSS Vectors/Payloads

1,338 269 Updated Jan 2, 2025

CTF write-ups

Python 99 25 Updated Sep 12, 2025

A tool to perform Sequential Import Chaining

Rust 282 14 Updated Sep 11, 2019
HTML 2 1 Updated Jul 21, 2020

A collection of browser-based side channel attack vectors.

757 51 Updated Mar 19, 2024

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Python 3,225 397 Updated Apr 18, 2023
Python 3 Updated Jul 23, 2018
Next