askifyouneed's Stars
OhShINT/ohshint.gitbook.io
So what is this all about? Yep, its an OSINT blog and a collection of OSINT resources and tools. Suggestions for new OSINT resources is always welcomed.
eu-digital-green-certificates/dgca-issuance-web
Repository for the dgca issuance web app.
projectdiscovery/nuclei-templates
Community curated list of templates for the nuclei engine to find security vulnerabilities.
infoslack/awesome-web-hacking
A list of web application security
wtsxDev/Penetration-Testing
List of awesome penetration testing resources, tools and other shiny things
Hack-with-Github/Awesome-Hacking
A collection of various awesome lists for hackers, pentesters and security researchers
devanshbatham/Awesome-Bugbounty-Writeups
A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference
trimstray/the-book-of-secret-knowledge
A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
Voorivex/pentest-guide
Penetration tests guide based on OWASP including test cases, resources and examples.
numirias/security
Some of my security stuff and vulnerabilities. Nothing advanced. More to come.
nu11secur1ty/CVE-mitre
https://cve.mitre.org/
worawit/CVE-2021-3156
Sudo Baron Samedit Exploit
nfsec/linux-backdoors
Simple linux backdoors and hiding techniques
calebshortt/opensshd_user_enumeration
OpenSSHD 7.2p2 - User Enumeration: CVE 2016-6210
KINGSABRI/godofwar
GodOfWar - Malicious Java WAR builder with built-in payloads
GrrrDog/weird_proxies
Reverse proxies cheatsheet
bl4de/dictionaries
Misc dictionaries for directory/file enumeration, username enumeration, password dictionary/bruteforce attacks
GrrrDog/Java-Deserialization-Cheat-Sheet
The cheat sheet about Java Deserialization vulnerabilities
BishopFox/GadgetProbe
Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.
frohoff/ysoserial
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
jakejarvis/awesome-shodan-queries
🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻
DominicBreuker/pspy
Monitor linux processes without root permissions
mishmashclone/carlospolop-privilege-escalation-awesome-scripts-suite
https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite
blaCCkHatHacEEkr/PENTESTING-BIBLE
articles
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
danielmiessler/SecLists
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.