Skip to content
View tgr420's full-sized avatar

Block or report tgr420

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Collection of documentation, tools, and tips related to vulnerability research.

Python 73 15 Updated Jun 9, 2026

SSRF (Server Side Request Forgery) testing resources

Python 2,504 494 Updated Oct 12, 2024

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

JavaScript 1,592 185 Updated Jan 16, 2026

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Python 251 58 Updated Dec 12, 2025

Write-ups of my findings.

123 24 Updated Sep 2, 2023

Find, verify, and analyze leaked credentials

Go 26,821 2,470 Updated Jun 18, 2026

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

Python 2,558 447 Updated Aug 3, 2024

A collection of custom security tools for quick needs.

Python 3,300 788 Updated May 1, 2023

HTTP Request Smuggling Detection Tool

Python 539 105 Updated Dec 21, 2023

Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!

Python 2,674 293 Updated Jun 11, 2026

Extracts URLs from OSINT Archives for Security Insights

Rust 186 17 Updated Jun 19, 2026

⚔️ A compiled list of companies who have active programs for responsible disclosure. MCP-enabled.

TypeScript 254 37 Updated Jun 19, 2026

Check if domain has bug bounty program or not

Python 28 10 Updated Jul 28, 2023

🐛 A list of writeups from the Google VRP Bug Bounty program

Python 1,625 273 Updated May 13, 2026

Tool to extract & validate google fcm server keys from apks

Python 31 9 Updated Jan 20, 2021

latest version of scanners for IIS short filename (8.3) disclosure vulnerability

Java 1,677 269 Updated Sep 3, 2023

Asset inventory of over 800 public bug bounty programs.

Shell 1,584 281 Updated Feb 14, 2025

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 71,631 25,028 Updated Jun 19, 2026

DNS Zone Transfer Testing Tool

Python 2 3 Updated Feb 24, 2025

Chrome Extension for Spidering a Website, which was started from google-site-spider.

JavaScript 12 7 Updated Sep 18, 2014
2 Updated Jun 19, 2025

Rockyou for web fuzzing

Go 3,172 539 Updated Mar 11, 2026

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Go 1,081 138 Updated Mar 24, 2026