Skip to content
View terjanq's full-sized avatar

Organizations

@xsleaks @googlers @justcatthefish @CTF-Organizers

Block or report terjanq

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

OWASP CRS (Official Repository)

Python 3,101 455 Updated May 1, 2026

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

JavaScript 16,942 843 Updated Apr 30, 2026

Web path scanner

Python 14,228 2,431 Updated Apr 29, 2026

Legend Agar.io Mod

JavaScript 28 131 Updated Apr 20, 2026

XS-Leaks Wiki

HTML 180 64 Updated Mar 13, 2026

Some setup scripts for security research tools.

Shell 9,383 1,914 Updated Mar 1, 2026

List of XSS Vectors/Payloads

1,371 272 Updated Jan 14, 2026

HTTPLeaks - All possible ways, a website can leak HTTP requests

HTML 2,104 208 Updated Jan 3, 2026

CTF write-ups

Python 100 25 Updated Sep 12, 2025

Implementation of attacks on cryptosystems

Python 76 14 Updated Jul 29, 2025

Content-Type Research

663 65 Updated Jun 29, 2025

A generator of weird files (binary polyglots, near polyglots, polymocks...)

Python 1,278 82 Updated Dec 22, 2024

ctf exploit codes or writeups

Python 159 16 Updated Dec 9, 2024

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

PHP 758 116 Updated May 6, 2024

A collection of browser-based side channel attack vectors.

757 55 Updated Mar 19, 2024

Prototype Pollution and useful Script Gadgets

1,616 223 Updated Jan 27, 2024

Reverse proxies cheatsheet

Python 1,863 221 Updated Nov 4, 2023

The cheat sheet about Java Deserialization vulnerabilities

3,175 600 Updated May 26, 2023
Jasmin 15 6 Updated May 1, 2023

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Python 3,348 401 Updated Apr 18, 2023

Collection of my capture-the-flag web challenge in any levels

PHP 120 34 Updated Jan 19, 2023

Searcher for cross-site leaks (XS-Leaks)

JavaScript 82 5 Updated Dec 27, 2022

Client Side Prototype Pollution Scanner

JavaScript 525 63 Updated Sep 17, 2022

Challenge repository for the watevrCTF 2019 CTF competition

C 37 10 Updated Jun 6, 2022

CTF writeups

JavaScript 30 7 Updated May 27, 2022

Same Origin XSS challenge

HTML 64 5 Updated Apr 7, 2022

Writeups for some CTF challenges. I keep the copy of task files in case you would like to try them yourself.

Python 12 Updated Oct 4, 2021

justCTF 2019 challenges sources

SystemVerilog 41 6 Updated Jun 9, 2021
Next