Stars
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints…
Incredibly fast crawler designed for OSINT.
Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥
PEDA - Python Exploit Development Assistance for GDB
Automated All-in-One OS Command Injection Exploitation Tool.
Server-Side Template Injection and Code Injection Detection and Exploitation Tool
Automatic SSRF fuzzer and exploitation tool
An advanced web directory & file scanning tool that will be more powerful than DirBuster, Dirsearch, cansina, and Yu Jian.一个高级web目录、文件扫描工具,功能将会强于DirBuster、Dirsearch、cansina、御剑。
JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.
SSRF (Server Side Request Forgery) testing resources
Tool for advanced mining for content on Github
Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner
This project has stopped to maintenance, please to https://github.com/knownsec/pocsuite3 project.
Shamelessly convert any Python 2 script into a terrible single line of code
RCE 0-day for GhostScript 9.50 - Payload generator
Herramienta para evadir disable_functions y open_basedir