0rgis

0rgis

Geek Repo

Location:Scotland

Home Page:https://deckchair.xyz

Twitter:@0rgis

Github PK Tool:Github PK Tool

0rgis's starred repositories

ladder

Selfhosted alternative to 12ft.io. and 1ft.io bypass paywalls with a proxy ladder and remove CORS headers from any URL

Language:GoLicense:GPL-3.0Stargazers:4325Issues:21Issues:36

GitTools

A repository with 3 tools for pwn'ing websites with .git repositories available

Language:ShellLicense:MITStargazers:3793Issues:89Issues:25

fuzzing

Tutorials, examples, discussions, research proposals, and other resources related to fuzzing

Language:C++License:Apache-2.0Stargazers:3414Issues:112Issues:29

FreeWifi

How to get free wifi.

Language:PythonLicense:NOASSERTIONStargazers:2872Issues:86Issues:19

CloudFlair

🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.

cariddi

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

Language:GoLicense:GPL-3.0Stargazers:1460Issues:13Issues:60

jsluice

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Language:GoLicense:MITStargazers:1306Issues:14Issues:12

gasmask

Information gathering tool - OSINT

Language:PythonLicense:GPL-3.0Stargazers:1183Issues:48Issues:56

GAP-Burp-Extension

Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist

webcopilot

An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities.

Language:ShellLicense:MITStargazers:1014Issues:10Issues:13

CMSmap

CMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs.

Language:PythonLicense:GPL-3.0Stargazers:1004Issues:27Issues:27

ScrapedIn

A tool to scrape LinkedIn without API restrictions for data reconnaissance

Penetration-List

Penetration-List: A comprehensive resource for testers, covering all types of vulnerabilities and materials used in Penetration Testing. Includes payloads, dorks, fuzzing materials, and offers in-depth theory sections. Visit our Medium profile for more information.

Language:PythonStargazers:750Issues:15Issues:0

alfred

Alfred is a advanced OSINT information gathering tool that finds social media accounts based on inputs.

Language:PythonLicense:MITStargazers:553Issues:8Issues:3

mantra

「🔑」A tool used to hunt down API key leaks in JS files and pages

Language:GoLicense:GPL-3.0Stargazers:553Issues:7Issues:2

CRLFsuite

The most powerful CRLF injection (HTTP Response Splitting) scanner.

Language:PythonLicense:MITStargazers:533Issues:9Issues:6

BruteXSS

BruteXSS is a tool written in python simply to find XSS vulnerabilities in web application. This tool was originally developed by Shawar Khan in CLI. I just redesigned it and made it GUI for more convienience.

Language:PythonLicense:GPL-3.0Stargazers:483Issues:16Issues:11

tartufo

Searches through git repositories for high entropy strings and secrets, digging deep into commit history

Language:PythonLicense:GPL-2.0Stargazers:454Issues:21Issues:173

kxss

This a adaption of tomnomnom's kxss tool with a different output format

Language:GoLicense:Apache-2.0Stargazers:400Issues:7Issues:17

WebHacking101

Web-App-Hacking-Notes

Language:PythonStargazers:358Issues:5Issues:0

porch-pirate

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API endpoints and secrets committed to workspaces, collections, requests, users and teams. Porch Pirate can be used as a client or be incorporated into your own applications.

Language:PythonLicense:GPL-3.0Stargazers:332Issues:4Issues:0

xss_vibes

A modern tool written in Python that automates your xss findings.

scan-for-webcams

scan for webcams on the internet

Language:PythonLicense:MITStargazers:245Issues:18Issues:8

DeHashed-API-Tool

A command-line tool to query the DeHashed API. Easily search for various parameters like usernames, emails, hashed passwords, IP addresses, and more.

Language:PythonLicense:GPL-3.0Stargazers:194Issues:5Issues:0

fetchmeurls

A Tool for Bug Bounty Hunters that uses Passive and Active Techniques to fetch URLs as a strong Recon, so you can then create Attack Vectors (XSS, Nuclei, SQLi etc...)

Language:ShellLicense:GPL-3.0Stargazers:57Issues:3Issues:0

crtsh

A Python Script to Get Subdomain using https://crt.sh

Language:PythonLicense:GPL-3.0Stargazers:54Issues:0Issues:0