Highlights
- Pro
Starred repositories
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
The recursive internet scanner for hackers. 🧡
An enterprise friendly way of detecting and preventing secrets in code.
pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching
A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.
A pentest reporting tool written in Python. Free yourself from Microsoft Word.
A simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issues
Find exposed API keys based on RegEx and get exploitation methods for some of keys that are found
Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.
A simple tool to detect vulnerabilities described here https://portswigger.net/research/browser-powered-desync-attacks.
Python script to check if there is any differences in responses of an application when the request comes from a search engine's crawler.