Lists (3)
Sort Name ascending (A-Z)
Stars
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
A collection of Semgrep rules derived from the OWASP MASTG specifically for Android applications.
Bypass Tiktok SSL pinning on Android devices.
PoC for a SMS-based shell. Send commands and receive responses over SMS from mobile broadband capable computers
A toolset for reverse engineering and fuzzing Protobuf-based apps
Beyond XSS: Explore the Web Front-end Security Universe. A series about front-end security
A cloudflare verification bypass script for webscraping
Top disclosed reports from HackerOne
A tool to find cloud buckets from Domains and Subdomains using Google, DNS, Gray Hat Warfare and all might Scraping
💀 Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh
GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)
Obtain GraphQL API schema even if the introspection is disabled
XENA is an innovative C2 made fully in Go. With hacking automation features.
Legitimate bug bounty programs value ethical practices and provide clear rewards to researchers for identifying security flaws
All the labs in this repository simulate real world bugs I found in the wild
Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.
A curated list of blockchain security Capture the Flag (CTF) competitions
A powerful asynchronous XSS scanner supporting up to 1,500 concurrent requests.
Powerful JavaScript bookmarklet designed for discovering and analyzing endpoints embedded in JavaScript files across various domains
A cheat sheet that contains advanced queries for SQL Injection of all types.
Insecure Firebase | Bugbounty | Hacking Insecure Firbase
A simple Python Exploit to Write Data to Insecure/vulnerable firebase databases! Commonly found inside Mobile Apps. If the owner of the app have set the security rules as true for both "read" & "wr…
A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
A handy phone call manager with phonebook, number blocking and multi-SIM support that uses truecaller to display the name of the caller.