Skip to content
View Mochazz's full-sized avatar
:octocat:
Just change 'Impossible' to 'I'm Possible'.
:octocat:
Just change 'Impossible' to 'I'm Possible'.

Block or report Mochazz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
47 stars written in Python
Clear filter

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 76,299 16,780 Updated Mar 16, 2026

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints…

Python 30,102 5,679 Updated Mar 23, 2026

Web path scanner

Python 14,114 2,430 Updated Mar 16, 2026

Incredibly fast crawler designed for OSINT.

Python 12,763 1,671 Updated Feb 10, 2026

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

Python 8,954 1,857 Updated Mar 22, 2024

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Python 7,400 1,168 Updated Aug 28, 2025

CTFs as you need them

Python 6,577 2,639 Updated Mar 20, 2026

PEDA - Python Exploit Development Assistance for GDB

Python 6,111 830 Updated Jul 29, 2024

Automated All-in-One OS Command Injection Exploitation Tool

Python 5,685 931 Updated Mar 22, 2026

宝塔Linux面板 - 简单好用的服务器运维面板

Python 4,508 1,014 Updated Dec 12, 2025

Server-Side Template Injection and Code Injection Detection and Exploitation Tool

Python 4,131 690 Updated Apr 21, 2024

Automatic SSRF fuzzer and exploitation tool

Python 3,509 567 Updated Sep 4, 2025

An advanced web directory & file scanning tool that will be more powerful than DirBuster, Dirsearch, cansina, and Yu Jian.一个高级web目录、文件扫描工具,功能将会强于DirBuster、Dirsearch、cansina、御剑。

Python 3,358 557 Updated Oct 21, 2025

Source Code Security Audit (源代码安全审计)

Python 3,190 941 Updated Sep 16, 2022

JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.

Python 2,922 422 Updated Nov 24, 2021

SSRF (Server Side Request Forgery) testing resources

Python 2,482 494 Updated Oct 12, 2024

Tool for advanced mining for content on Github

Python 2,153 431 Updated Nov 5, 2025

Notes about attacking Jenkins servers

Python 2,089 330 Updated Jul 10, 2024

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Python 1,921 405 Updated Apr 13, 2022

This project has stopped to maintenance, please to https://github.com/knownsec/pocsuite3 project.

Python 1,821 595 Updated May 27, 2022

Shamelessly convert any Python 2 script into a terrible single line of code

Python 1,527 112 Updated May 18, 2025

PHP Internals Book

Python 1,429 179 Updated Aug 27, 2025

一键ThinkPHP漏洞检测

Python 1,164 182 Updated Nov 1, 2023

SvnExploit支持SVN源代码泄露全版本Dump源码

Python 1,027 172 Updated Dec 20, 2022

An Easy / Quick / Cheap Integrated Platform

Python 651 136 Updated Dec 12, 2022

RCE 0-day for GhostScript 9.50 - Payload generator

Python 543 107 Updated Sep 8, 2021

Herramienta para evadir disable_functions y open_basedir

Python 487 101 Updated Sep 5, 2023

提取远程 git 泄露或本地 git 的工具

Python 484 57 Updated May 23, 2024

Rogue MySql Server

Python 473 273 Updated Sep 15, 2013

Some tools for CTF off line

Python 447 97 Updated Apr 21, 2018
Next