Skip to content
View cure53's full-sized avatar

Sponsors

@dcramer
@jgraph
@healthchecks
@hata6502
@cybozu

Block or report cure53

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A small collection of potentially useful contract templates

414 63 Updated May 30, 2025

rewrite constructor arguments, call DOMPurify, profit

JavaScript 71 7 Updated Sep 24, 2024

Use DOMPurify on server and client in the same way

JavaScript 535 17 Updated Dec 16, 2025

A manager for your secrets.

JavaScript 954 92 Updated Jul 13, 2024

Some public notes

1,276 76 Updated Jul 13, 2019

A toolset for reverse engineering and fuzzing Protobuf-based apps

Python 1,595 195 Updated Dec 19, 2025

Enumerate Typo3 version and extensions

Python 176 32 Updated Jul 2, 2024

A collection of JavaScript engine CVEs with PoCs

2,308 404 Updated Sep 3, 2019

SSH server auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc)

Python 2,986 267 Updated Jun 28, 2024

TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.

Java 1,648 244 Updated May 25, 2024

Write any JavaScript with 6 Characters: []()!+

JavaScript 8,541 685 Updated Mar 10, 2025

Rip web accessible (distributed) version control systems: SVN/GIT/HG...

Perl 1,776 318 Updated Jul 19, 2024

Smallest possible syntactically valid files of different types

HTML 2,276 193 Updated Jul 18, 2024

A weekly selection of the relevant Chromium and Firefox intents

272 2 Updated Jan 19, 2025

A Firefox extension for whitelist driven safe JavaScript execution.

JavaScript 80 16 Updated Jul 25, 2018

minimalistic secure XMPP client in OCaml

OCaml 253 19 Updated Oct 21, 2024

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 67,651 24,823 Updated Dec 19, 2025
Bikeshed 258 33 Updated Nov 24, 2025

Attack Surface Management Platform

Shell 9,274 2,004 Updated Sep 27, 2025

XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.

PHP 1,745 351 Updated Sep 12, 2020

user.js -- Firefox configuration hardening

JavaScript 2,861 235 Updated Oct 8, 2025
Java 32 10 Updated Aug 5, 2015

WS-Attacker is a modular framework for web services penetration testing. It is developed by the Chair of Network and Data Security, Ruhr University Bochum (https://nds.rub.de/ ) and the Hackmanit G…

Java 487 116 Updated Oct 3, 2024

RIPS - A static source code analyser for vulnerabilities in PHP scripts

PHP 361 62 Updated May 21, 2016

Magic hashes – PHP hash "collisions"

807 106 Updated Mar 23, 2025

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

JavaScript 4,036 434 Updated Dec 12, 2025

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

JavaScript 16,409 820 Updated Dec 8, 2025

jPurify

JavaScript 64 9 Updated Feb 16, 2017
Next