cr1f's Stars
yt-dlp/yt-dlp
A feature-rich command-line audio/video downloader
juliocesarfort/public-pentesting-reports
A list of public penetration test reports published by several consulting firms and academic security groups.
securego/gosec
Go security checker
blacklanternsecurity/bbot
The recursive internet scanner for hackers. 🧡
Threekiii/Awesome-POC
一个漏洞POC知识库 目前数量 1000+
safe6Sec/Fastjson
Fastjson姿势技巧集合
abrahamjuliot/creepjs
Creepy device and browser fingerprinting
BishopFox/jsluice
Extract URLs, paths, secrets, and other interesting bits from JavaScript
vladko312/SSTImap
Automatic SSTI detection tool with interactive interface
cckuailong/JNDI-Injection-Exploit-Plus
80+ Gadgets(30 More than ysoserial). JNDI-Injection-Exploit-Plus is a tool for generating workable JNDI links and provide background services by starting RMI server,LDAP server and HTTP server.
trickest/resolvers
The most exhaustive list of reliable DNS resolvers.
vortexau/dnsvalidator
Maintains a list of IPv4 DNS servers by verifying them against baseline servers, and ensuring accurate responses.
0xacb/viewgen
Viewgen is a ViewState tool capable of generating both signed and encrypted payloads with leaked validation keys
dolevf/graphw00f
graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.
blacklanternsecurity/badsecrets
A library for detecting known secrets across many web frameworks
su18/hack-fastjson-1.2.80
ewilded/shelling
SHELLING - a comprehensive OS command injection payload generator
ambionics/cnext-exploits
Exploits for CNEXT (CVE-2024-2961), a buffer overflow in the glibc's iconv()
bndeff/socksdroid
nicholasaleks/graphql-threat-matrix
GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations
huntergregal/PNG-IDAT-Payload-Generator
Generate a PNG with a payload embedded in the IDAT chunk (Based off of previous concepts and code -- credit in README)
ambionics/wrapwrap
Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.
BishopFox/CVE-2023-27997-check
Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing
DistriNet/timeless-timing-attacks
A Python implementation that facilitates finding timeless timing attack vulnerabilities.
p1n93r/SpringBootAdmin-thymeleaf-SSTI
SpringBootAdmin-thymeleaf-SSTI which can cause RCE
MayankPandey01/Sparty-2.0
An MS Sharepoint and Frontpage Auditing Tool
xoocoon/hp-15-ew0xxx-snd-fix
DKMS module for fixing the sound on Linux for HP models Envy x360 15-ew0xxx
DistriNet/evil-epubs
Using EPUBs for the semi-automated evaluation of security and privacy implications of EPUB reading systems.
W01fh4cker/CVE-2024-30043-XXE
Exploiting XXE Vulnerabilities on Microsoft SharePoint Server and Cloud via Confused URL Parsing
michurin/xterm256-color-picker
Online color picker for terminal 256 color palette. Examples for shell prompt, vim, term/xterm