Pinned Repositories
Awesome-Hacking-Resources
A collection of hacking / pentetration testing resources to make you better!
burplist
BurpSmartBuster
A Burp Suite content discovery plugin that add the smart into the Buster!
CT_subdomains
An hourly updated list of subdomains gathered from certificate transparency logs
CTF-Difficulty
This cheasheet is aimed at the CTF Players and Beginners to help them sort the CTF Challenges on the basis of Difficulties.
domain-scan
A local or Lambda-based pipeline for scanning domains to measure things like HTTPS and accessibility.
domdig
DOM XSS scanner for Single Page Applications
fronter
Find frontable domains
Open_OSINT_Team_Links
Links for the Open OSINT Slack Team
SPSE
SPSE Exercises
Hax0rG1rl's Repositories
Hax0rG1rl/SPSE
SPSE Exercises
Hax0rG1rl/Penetration-Test-Report-Generator
An application to generate penetration test reports using templates and uploaded xml files from various supported tools.
Hax0rG1rl/attacking-drupal
Scripts used to augment the penetration testing process of Drupal web applications.
Hax0rG1rl/cintruder
Captcha Intruder
Hax0rG1rl/crossdomain-exploitation-framework
Everything you need to exploit overly permissive crossdomain.xml files
Hax0rG1rl/dictator
Custom dictionary generation framework intended for enumertion of URL-s (directories, variables). With a bit of adjustment it would also be a good fit for passwords as well.
Hax0rG1rl/GWT-Penetration-Testing-Toolset
A set of tools made to assist in penetration testing GWT applications. Additional details about these tools can be found on my OWASP Appsec DC slides available here: http://www.owasp.org/images/7/77/Attacking_Google_Web_Toolkit.ppt
Hax0rG1rl/GzipBloat
PHP framework to test User-Agents and intermediary content inspection devices for denial-of-service vulnerabilities with respect to HTTP response decompression.
Hax0rG1rl/haskell-from-python
Example how to call Haskell from Python easily (using ctypes.cdll.LoadLibrary)
Hax0rG1rl/pywebfuzz
fork of pywebfuzz
Hax0rG1rl/quickjack
Quickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.
Hax0rG1rl/SAP-Stuff
Hax0rG1rl/sparty
Sparty - MS Sharepoint and Frontpage Auditing Tool [Unofficial]
Hax0rG1rl/ss7calc
SS7calc - SS7 Signaling Point Code calculator
Hax0rG1rl/T3Scan
T3Scan is an analyse tool for TYPO3 CMS powered websites.
Hax0rG1rl/vulnerable_xxe
A C# web handler that is vulnerable to XXE with PoC. This is to serve as an example of what vulnerable C# code looks like.
Hax0rG1rl/xss.swf
a tiny tool for swf hacking, just browse it:)
Hax0rG1rl/xsschef
Chrome extension Exploitation Framework
Hax0rG1rl/zip-bomb
scripts to create zip bombs