Voorivex's Stars
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
enaqx/awesome-pentest
A collection of awesome penetration testing resources, tools and other shiny things
vulhub/vulhub
Pre-Built Vulnerable Environments Based on Docker-Compose
maurosoria/dirsearch
Web path scanner
nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters
A list of resources for those interested in getting started in bug bounties
chaitin/xray
一款完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档
nomi-sec/PoC-in-GitHub
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
0xInfection/Awesome-WAF
🔥 Web-application firewalls (WAFs) from security standpoint.
drk1wi/Modlishka
Modlishka. Reverse Proxy.
s0md3v/AwesomeXSS
Awesome XSS stuff
dwisiswant0/awesome-oneliner-bugbounty
A collection of awesome one-liner scripts especially for bug bounty tips.
christophetd/CloudFlair
🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.
threedr3am/learnjavabug
Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。
devanshbatham/ParamSpider
Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
joaomatosf/jexboss
JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool
iddoeldor/frida-snippets
Hand-crafted Frida examples
inonshk/31-days-of-API-Security-Tips
This challenge is Inon Shkedy's 31 days API Security Tips.
B3nac/Android-Reports-and-Resources
A big list of Android Hackerone disclosed reports and other resources.
orangetw/awesome-jenkins-rce-2019
There is no pre-auth RCE in Jenkins since May 2017, but this is the one!
hypn0s/AJPy
SpiderLabs/DoHC2
DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH).
zricethezav/h1domains
HackerOne "in scope" domains
Edu4rdSHL/tor-router
A tool that allows you to make TOR your default gateway and send all internet connections under TOR (as transparent proxy) to increase privacy/anonymity without extra unnecessary code.
onionj/pybotnet
PyBotNet: A Remote Control Framework for Python with Telegram Integration
SpiderLabs/CryptOMG
CryptOMG is a configurable CTF style test bed that highlights common flaws in cryptographic implementations.
erforschr/bruteforce-http-auth
Bruteforce HTTP Authentication
byt3bl33d3r/Slides
Slides from various talks that I've given over the years
teambi0s/dfunc-bypasser
This tool is for letting you know how strong your disable_functions is and how you can bypass that.
YouGina/reconmaster
ReconMaster contest - scripts used and a write-up
dxa4481/AttackingAndDefendingTheGCPMetadataAPI
This repo gives an overview of some GCP metadata API attack and defend patterns