- All languages
- ActionScript
- Assembly
- Batchfile
- BlitzBasic
- Bluespec
- Boo
- C
- C#
- C++
- CSS
- Classic ASP
- Dart
- Dockerfile
- Go
- HTML
- Hack
- Haskell
- Java
- JavaScript
- Jupyter Notebook
- Kotlin
- LLVM
- LabVIEW
- Lua
- Markdown
- Mathematica
- Meson
- Nim
- OCaml
- Objective-C
- PHP
- Pascal
- Perl
- PowerShell
- Python
- Raku
- Roff
- Ruby
- Rust
- SCSS
- Scala
- Shell
- Smali
- Smarty
- Swift
- TSQL
- TypeScript
- VBA
- Visual Basic
- Vue
- XSLT
- YARA
Starred repositories
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
The classic email sending library for PHP
Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
A curated list of resources for learning about application security
SQLI labs to test error based, Blind boolean based, Time based.
PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.
The osTicket open source ticketing system official project repository, for versions 1.8 and later
All in one tool for Information Gathering, Vulnerability Scanning and Crawling. A must have tool for all penetration testers
Collection of CTF Web challenges I made
A collection of PHP backdoors. For educational or testing purposes only.
AWSGoat : A Damn Vulnerable AWS Infrastructure
Common PHP webshells you might need for your Penetration Testing assignments or CTF challenges. Do not host the file(s) on your server!
OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an easy-to-use web hacking environment designed for labs, s…
FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sending of emails, and much more.
Various webshells. We accept pull requests for additions to this collection.
Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation junction for each target / url found.
A collection of PHP exploit scripts, found when investigating hacked servers. These are stored for educational purposes and to test fuzzers and vulnerability scanners. Feel free to contribute.
🎯 PHP / ASP - Shell Backdoor List 🎯
This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack
WhiteWinterWolf's PHP web shell