h1pmnh
Hacking on Synack, HackerOne and Bugcrowd as pmnh - posting interesting tools in this repo, please comment/share/contribute!
h1pmnh's Stars
FiloSottile/mkcert
A simple zero-config tool to make locally trusted development certificates with any names you'd like.
LandGrey/SpringBootVulExploit
SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list
Ekultek/WhatWaf
Detect and bypass web application firewalls and protection systems
BishopFox/cloudfox
Automating situational awareness for cloud penetration tests.
mandatoryprogrammer/xsshunter-express
An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!
rootsecdev/Azure-Red-Team
Azure Security Resources and Notes
hakluke/weaponised-XSS-payloads
XSS payloads designed to turn alert(1) into P1
ptoomey3/evilarc
Create tar/zip archives that can exploit directory traversal vulnerabilities
pwm-project/pwm
pwm
bitquark/shortscan
An IIS short filename enumeration tool
disclose/bug-bounty-platforms
A community-powered collection of all known bug bounty platforms, vulnerability disclosure platforms, and crowdsourced security platforms currently active on the Internet.
blacklanternsecurity/badsecrets
A library for detecting known secrets across many web frameworks
pawitp/protobuf-decoder
JavaScript-based web UI to decode ad-hoc Protobuf data
jthack/PIPE
Prompt Injection Primer for Engineers
lanjelot/kb
All my infosec notes I have been building up over the years
noobpk/frida-intercept-encrypted-api
A tool to help you intercept encrypted APIs in iOS or Android apps
makuga01/dnsFookup
DNS rebinding toolkit
X1r0z/ActiveMQ-RCE
ActiveMQ RCE (CVE-2023-46604) 漏洞利用工具
nikitastupin/param-miner-doc
Unofficial documentation for the great tool Param Miner
horizon3ai/CVE-2023-34362
MOVEit CVE-2023-34362
ARPSyndicate/kenzer-templates
essential templates for kenzer [DEPRECATED]
projectmonke/shortnameguesser
A tool to guess the rest of the shortnames provided by vulnerable IIS instances.
CanardMandarin/csp-bypass
Need any help bypassing CSP ?
codeplutos/MySQL-JDBC-Deserialization-Payload
MySQL JDBC Deserialization Payload / MySQL客户端jdbc反序列化漏洞payload
hieuminhnv/CVE-2022-21587-POC
CVE-2022-21587 POC
JeffJerseyCow/eviloauth
OAuth 2.0 exploitation, attack and research tools.
MSU-NatSci/MuraCMS
A copy of Mura when it was still open-source in August 2020
irsdl/BlazorTrafficProcessor
pingidentity/bug-bounty-server-profiles
0xDexter0us/h1-scope-fetcher
A tool to fetch all in scope assets of HackerOne programs for integration in your automation and hacking workflow using HackerOne's hacker API