Pinned Repositories
badtf
BurpAutoScan
Setup to scan local app with AutoScanWithBurp
BurpCheatSheet
A cheat sheet for BurpSuite
burpextensions
Random bunch of Burp extensions
ctf_apps
Vulnerable applications
security-resources
A security testing resource wiki
mccabe615's Repositories
mccabe615/badtf
mccabe615/BurpAutoScan
Setup to scan local app with AutoScanWithBurp
mccabe615/aws-metadata-proxy
AWS Metadata Proxy for protection against SSRF
mccabe615/cloud_metadata_ips
List of special metadata IPs used in cloud services
mccabe615/codesamples
A sample of vulnerable examples
mccabe615/Damn-Vulnerable-Redis-Container
An example of obtaining RCE via Redis and CSRF
mccabe615/DangerousRubyFunctions
List of dangerous Ruby functions
mccabe615/dcaf_case_management
Rails-based case management system for the DC Abortion Fund
mccabe615/django-DefectDojo
DefectDojo is an open-source application vulnerability correlation and security orchestration tool.
mccabe615/dondada
mccabe615/ebooks.py
Lambda based ebooks Tweeter
mccabe615/gha-test
mccabe615/haml_xss_example
Copy of Todo app to demo HAML XSS vulnerability
mccabe615/railsgoat
A vulnerable version of Rails that follows the OWASP Top 10
mccabe615/retiree
A gem wrapper around retire.js
mccabe615/sql-injections-examples
mccabe615/cloudsplaining
Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.
mccabe615/ListOfHacks
List of web app based hacks
mccabe615/micropurchase
18F's micro-purchase threshold experiment management app.
mccabe615/node-js-sample
A barebones Node.js app using the Express framework.
mccabe615/php-exploit-scripts
A collection of PHP exploit scripts, found when investigating hacked servers. These are stored for educational purposes and to test fuzzers and vulnerability scanners. Feel free to contribute.
mccabe615/pocs
mccabe615/rubocop-github
Code style checking for GitHub Ruby repositories
mccabe615/scryptauth
A scrypt password hash encoding proposal and implementation for go
mccabe615/security-guide-for-developers
Security Guide for Developers
mccabe615/SecurityTools
A single repository for any security tools, scripts, documentation, etc. that I add
mccabe615/semgrep-rules
Semgrep rules registry
mccabe615/terra-fied
mccabe615/weirdAAL
WeirdAAL (AWS Attack Library)
mccabe615/xxeserve
XXE Out of Band Server.