Skip to content
View terjanq's full-sized avatar

Organizations

@xsleaks @googlers @justcatthefish @CTF-Organizers

Block or report terjanq

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Searcher for cross-site leaks (XS-Leaks)

JavaScript 83 5 Updated Dec 27, 2022

Automated security reporting from markdown templates (HackerOne and Bugcrowd are currently the platforms supported)

Shell 457 68 Updated May 10, 2019

OWASP CRS (Official Repository)

Python 2,907 430 Updated Dec 17, 2025

Same Origin XSS challenge

HTML 64 5 Updated Apr 7, 2022

XS-Leaks Wiki

HTML 170 54 Updated May 29, 2025

A generator of weird files (binary polyglots, near polyglots, polymocks...)

Python 1,257 82 Updated Dec 22, 2024

Client Side Prototype Pollution Scanner

JavaScript 522 63 Updated Sep 17, 2022

Prototype Pollution and useful Script Gadgets

1,550 216 Updated Jan 27, 2024

Writeups for some CTF challenges. I keep the copy of task files in case you would like to try them yourself.

Python 12 Updated Oct 4, 2021

CTF writeups

JavaScript 30 7 Updated May 27, 2022

Content-Type Research

647 66 Updated Jun 29, 2025

The cheat sheet about Java Deserialization vulnerabilities

3,156 601 Updated May 26, 2023

Reverse proxies cheatsheet

Python 1,853 219 Updated Nov 4, 2023

A JavaScript sandbox using proxies

JavaScript 20 2 Updated Jul 18, 2020

justCTF 2019 challenges sources

SystemVerilog 39 6 Updated Jun 9, 2021

Challenge repository for the watevrCTF 2019 CTF competition

C 37 10 Updated Jun 6, 2022

ctf exploit codes or writeups

Python 160 16 Updated Dec 9, 2024

Implementation of attacks on cryptosystems

Python 75 14 Updated Jul 29, 2025

HTTPLeaks - All possible ways, a website can leak HTTP requests

HTML 2,076 206 Updated Oct 23, 2024

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

JavaScript 16,395 820 Updated Dec 8, 2025

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

PHP 736 111 Updated May 6, 2024

List of XSS Vectors/Payloads

1,347 269 Updated Jan 2, 2025

CTF write-ups

Python 100 25 Updated Sep 12, 2025

A tool to perform Sequential Import Chaining

Rust 283 14 Updated Sep 11, 2019
HTML 2 1 Updated Jul 21, 2020

A collection of browser-based side channel attack vectors.

755 52 Updated Mar 19, 2024

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Python 3,253 397 Updated Apr 18, 2023
Python 3 Updated Jul 23, 2018
Next