Skip to content
View hex0wn's full-sized avatar
🏠
Working from home<img>[aa">xxx](a">xxx)
🏠
Working from home<img>[aa">xxx](a">xxx)

Block or report hex0wn

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Allow AI to wade through complex OpenAPIs using Simple Language

TypeScript 865 90 Updated Oct 26, 2025

Convert Any OpenAPI V3 API to MCP Server

Go 586 70 Updated Apr 3, 2025

Exploits for CNEXT (CVE-2024-2961), a buffer overflow in the glibc's iconv()

Python 499 60 Updated Sep 30, 2024

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

OCaml 13,699 845 Updated Dec 25, 2025

Pwn stuff.

PHP 1,807 392 Updated May 31, 2022
Go 558 75 Updated Mar 27, 2025

Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3

Python 2,042 329 Updated Jan 2, 2024

🕵️‍♂️ Offensive Google framework.

Python 18,214 1,555 Updated Oct 4, 2025

Custom Selenium Chromedriver | Zero-Config | Passes ALL bot mitigation systems (like Distil / Imperva/ Datadadome / CloudFlare IUAM)

Python 12,147 1,309 Updated Jul 5, 2025

A repository containing research regarding various Anti-DDoS systems. (CloudFlare)

271 28 Updated Aug 25, 2023

Bypass Coudflare bot protection using Cloudflare Workers

JavaScript 790 109 Updated Jul 27, 2021

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

JavaScript 579 90 Updated Jun 22, 2020

🐛 A list of writeups from the Google VRP Bug Bounty program

Python 1,393 235 Updated Nov 11, 2025

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that domain. Handy for bugbounty hunters.

Shell 1,262 262 Updated Sep 5, 2022

Multi-layer Recurrent Neural Networks (LSTM, GRU, RNN) for character-level language models in Torch

Lua 11,937 2,625 Updated Oct 24, 2023

Directory/File, DNS and VHost busting tool written in Go

Go 13,180 1,536 Updated Dec 23, 2025

Viewgen is a ViewState tool capable of generating both signed and encrypted payloads with leaked validation keys

Python 653 88 Updated Feb 1, 2025

📦 Make security testing of K8s, Docker, and Containerd easier.

Go 4,507 591 Updated Nov 5, 2025

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)

C 3,289 533 Updated Dec 21, 2025

A collection of android security related resources

Shell 9,044 1,528 Updated Dec 22, 2025

A collection of various awesome lists for hackers, pentesters and security researchers

103,184 9,804 Updated Jan 18, 2025

Awesome Frida - A curated list of Frida resources http://www.frida.re/ (https://github.com/frida/frida)

3,381 362 Updated Jan 5, 2024

ssl_logger based on frida

Python 586 149 Updated Jul 29, 2022

Community curated list of public bug bounty and responsible disclosure programs.

Go 1,262 384 Updated Nov 24, 2025

POC for GitLabs Authenticated RCE in version 11.4.7 community edition

Python 13 13 Updated Feb 8, 2021

Static page generator for documenting GraphQL Schema

TypeScript 1,567 133 Updated Jan 31, 2023

Electron JS Browser To Find XSS Vulnerabilities Automatically

JavaScript 746 124 Updated Mar 30, 2021

PoC for CVE-2021-3156 (sudo heap overflow)

C 434 108 Updated Apr 14, 2022

Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules thro…

Java 1,763 341 Updated Apr 26, 2024
Next