Stars
PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack
365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack.
PHP shells that work on Linux OS, macOS, and Windows OS.
Challenges & author writeups from ZeroDays CTF 2025.
This is my personal repo, which includes bug bounty tips, a collection of tools, one-liners, and other resources I personally prefer while hunting. It is still under development, so feel free to co…