Pinned Repositories
230-OOB
An Out-of-Band XXE server for retrieving file contents over FTP.
brute53
A tool to bruteforce nameservers when working with subdomain delegations to AWS.
cspparse
A tool to evaluate Content Security Policies.
gau
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.
hacks
Repo of useful scripts
jenkinz
jenkinz is a tool to retrieve every build for every job ever created and run on a given Jenkins instance.
otxurls
Fetch known urls from AlienVault's Open Threat Exchange for given hosts
secretz
secretz, minimizing the large attack surface of Travis CI
subjs
Fetches javascript file from a list of URLS or subdomains.
theftfuzzer
TheftFuzzer is a tool that fuzzes Cross-Origin Resource Sharing implementations for common misconfigurations.
lc's Repositories
lc/gau
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.
lc/subjs
Fetches javascript file from a list of URLS or subdomains.
lc/secretz
secretz, minimizing the large attack surface of Travis CI
lc/theftfuzzer
TheftFuzzer is a tool that fuzzes Cross-Origin Resource Sharing implementations for common misconfigurations.
lc/230-OOB
An Out-of-Band XXE server for retrieving file contents over FTP.
lc/hacks
Repo of useful scripts
lc/cspparse
A tool to evaluate Content Security Policies.
lc/jenkinz
jenkinz is a tool to retrieve every build for every job ever created and run on a given Jenkins instance.
lc/otxurls
Fetch known urls from AlienVault's Open Threat Exchange for given hosts
lc/brute53
A tool to bruteforce nameservers when working with subdomain delegations to AWS.
lc/DOD-Recon
Recon for Department of Defense HackerOne program
lc/research
miscellaneous security research stuff
lc/rickrolllogs
tool to rick roll access.logs
lc/reckdns
A kinda reckless dns resolver. Still under development.
lc/rlyCTF
rlyCTF (relay CTF) challenge to emulate real-world SSRF attacks.
lc/sslc2
Simple C&C example in assembly that retrieves commands from the Organizational Unit (OU) field in an SSL certificate
lc/bugbountylink
URL Shortener using Flask & MySQL
lc/lc.github.io
Information Security blog by Corben Leo @hacker_
lc/newsletter-code
Repository for any code I send out in newsletters.
lc/pfzf
fzf for yanking code/workspace context for LLM workflows.
lc/certspotter
Certificate Transparency Log Monitor
lc/ds_storescanner
A tool to scan for .DS_Store files on webservers
lc/upload-scanner
HTTP file upload scanner for Burp Proxy
lc/ctf-dev
Various CTF's I've created over time
lc/color
Color package for Go (golang)
lc/ffuf
Fast web fuzzer written in Go
lc/safewrite
simple golang library for safe/multi-threaded file writing
lc/trufflehog
Find and verify credentials
lc/zgrab2
Fast Go Application Scanner
lc/buz
Serverless multi-protocol + multi-destination event collection system.