Skip to content
View tolo7010's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report tolo7010

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

A LLM explicitly designed for getting hacked

Python 165 28 Updated Aug 2, 2023

Nginx configuration static analyzer

Python 8,546 443 Updated Jul 28, 2024

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

HTML 1,317 328 Updated Jan 10, 2025

Prompt Injection Primer for Engineers

538 62 Updated Aug 25, 2023

AppSec Ezine Public Repository.

1,209 105 Updated Nov 14, 2025

Cloud Security Posture Management (CSPM)

JavaScript 3,659 733 Updated Dec 4, 2025

An IIS short filename enumeration tool

Go 1,051 110 Updated Nov 25, 2024

Collections of Orange Tsai's public presentation slides.

749 76 Updated Jan 1, 2025

Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable SSRF candidates.

Go 699 52 Updated Dec 19, 2023

Mastering Ethereum: 2nd Edition, by Andreas M. Antonopoulos, Gavin Wood, Carlo Parisi, Alessandro Mazza, Niccolò Pozzolini

21,342 5,203 Updated Dec 19, 2025

Basics on commands/tools/info on how to assess the security of mobile applications

1,628 255 Updated Dec 19, 2023

A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting

1,694 236 Updated Sep 29, 2025

Fast and customizable subdomain wordlist generator using DSL

Go 902 67 Updated Dec 11, 2025

Mass scanner for the Java serialize bug

Python 152 35 Updated Jun 16, 2025

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.

C 4,298 509 Updated Dec 18, 2025

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Shell 9,888 936 Updated Dec 23, 2025

A curated list of various bug bounty tools

5,631 888 Updated Nov 30, 2025

😱 A curated list of amazingly awesome OSINT

24,029 3,340 Updated Dec 13, 2025

A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.

Python 1,274 240 Updated Aug 18, 2025

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

880 219 Updated Dec 15, 2025

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.

JavaScript 1,667 350 Updated May 24, 2025

Reverse proxies cheatsheet

Python 1,852 220 Updated Nov 4, 2023

CORS Misconfiguration Scanner

Python 1,483 187 Updated Sep 17, 2022

This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.

1,682 422 Updated Jun 20, 2022

Welcome to the XSS Challenge Wiki!

1,597 222 Updated Jun 24, 2020

Run a docker container include hackazon, apache, and mysql

Shell 16 18 Updated Oct 22, 2022

XVWA on LAMP base docker image

Shell 44 12 Updated Nov 16, 2018

Damn Vulnerable NodeJS Application

SCSS 756 838 Updated Mar 27, 2024
Next