Starred repositories
Find, verify, and analyze leaked credentials
an awesome list of honeypot resources
NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.
A python Flask app that generates dynamic DTDs for easy out-of-band data exfiltration.
Tool for catching and logging different types of requests.
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
Collection of methodology and test case for various web vulnerabilities.
A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
Decipher hashes using online rainbow & lookup table attack services.
A tool for embedding XXE/XML exploits into different filetypes
Reconnaissance tool for GitHub organizations
A web crawler written with pentesting in mind and some hacks for smart crawling
Proof-of-concept codes created as part of security research done by Google Security Team.
A collection of Windows, Linux and MySQL privilege escalation scripts and exploits.
Automatic SQL injection and database takeover tool
Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.
Veil Evasion is no longer supported, use Veil 3.0!
The legacy Exploit Database repository - New repo located at https://gitlab.com/exploit-database/exploitdb
Plugin for Burp Suite Free wich detects dynamic JS generated on the server side
A Burp Suite extension for CSRF proof of concepts.
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
A CRLF ( Carriage Return Line Feed ) Injection attack occurs when a user manages to submit a CRLF into an application. This is most commonly done by modifying an HTTP parameter or URL.
sbzo / SSRF-Testing
Forked from cujanovic/SSRF-TestingSSRF (Server Side Request Forgery) testing resources