Skip to content
View h4x0rl33tx's full-sized avatar
🥷
Hunting
🥷
Hunting

Block or report h4x0rl33tx

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
18 stars written in Python
Clear filter

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 75,018 16,603 Updated Feb 2, 2026

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Python 7,352 1,164 Updated Aug 28, 2025

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Python 5,545 793 Updated Feb 8, 2025

💀 Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh

Python 3,600 465 Updated Nov 14, 2025

针对SpringBoot的开源渗透框架,以及Spring相关高危漏洞利用工具

Python 2,210 180 Updated Nov 9, 2025

Autoswagger by Intruder - detect API auth weaknesses

Python 1,826 161 Updated Aug 8, 2025

Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more.

Python 1,328 165 Updated Aug 6, 2025

REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications

Python 1,287 146 Updated Aug 7, 2025

专为CTF设计的Jinja2 SSTI全自动绕WAF脚本 | A Jinja2 SSTI cracker for bypassing WAF, designed for CTF

Python 1,222 71 Updated Feb 8, 2026

A collection of AWS penetration testing junk

Python 1,216 196 Updated Aug 30, 2023

60k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒

Python 1,191 150 Updated Feb 7, 2026

Latest CVEs with their Proof of Concept exploits.

Python 1,125 134 Updated Jan 23, 2026

HackerOne "in scope" domains

Python 498 134 Updated Feb 8, 2026

HackerOne资产更新 | 每日更新HackerOne资产,对HackerOne的资产进行爬行和整理,SRC资产更新仅会增加,不会进行删除,每天更新的可以进行差异化对比来获取到新的项目资产范围

Python 312 228 Updated Feb 7, 2026

BurnWP Advanced Exploiter System instead Scanner & Custom Plugin for Pentester

Python 82 25 Updated Oct 5, 2025

A security research tool designed to intercept and analyze OAuth requests.

Python 6 Updated Feb 20, 2025

Generate HTML/SVG payloads for testing Server-Side Request Forgery vulnerabilities

Python 1 Updated Dec 5, 2025