0xJeti's starred repositories

DefaultCreds-cheat-sheet

One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️

Language:PythonLicense:MITStargazers:5488Issues:88Issues:16

jwt_tool

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Language:PythonLicense:GPL-3.0Stargazers:5234Issues:65Issues:77

Java-Deserialization-Cheat-Sheet

The cheat sheet about Java Deserialization vulnerabilities

security-research-pocs

Proof-of-concept codes created as part of security research done by Google Security Team.

Language:C++License:Apache-2.0Stargazers:1850Issues:174Issues:0

x8

Hidden parameters discovery suite

Language:RustLicense:GPL-3.0Stargazers:1633Issues:23Issues:51

requests-ip-rotator

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

Language:PythonLicense:GPL-3.0Stargazers:1291Issues:17Issues:59

ysomap

A helpful Java Deserialization exploit framework.

Language:JavaLicense:Apache-2.0Stargazers:1148Issues:29Issues:16

can-i-take-over-dns

"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.

Language:GoLicense:UnlicenseStargazers:527Issues:16Issues:15

ppmap

A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.

Language:GoLicense:GPL-3.0Stargazers:486Issues:13Issues:15

gotator

Gotator is a tool to generate DNS wordlists through permutations.

Language:GoLicense:GPL-3.0Stargazers:442Issues:6Issues:12

image-upload-exploits

This repository contains various media files for known attacks on web applications processing media files. Useful for penetration tests and bug bounty.

Language:PostScriptStargazers:310Issues:8Issues:0

sns

IIS shortname scanner written in Go

Language:GoLicense:Apache-2.0Stargazers:295Issues:6Issues:5

pwn-machine

PwnMachine is a self hosting solution based on docker aiming to provide an easy to use pwning station for bug hunters.

Language:VueLicense:GPL-3.0Stargazers:292Issues:16Issues:18

Cloud-Pentesting

This repository is in progress, it will keep updating as I come across to new learning materials. Feel free to contribute.

FileChangeMonitor

Continuous monitoring for JavaScript files

Key-Checker

Go scripts for checking API key / access token validity

Language:GoLicense:MITStargazers:210Issues:6Issues:2

AndroidSecNotes

An actively maintained, Self curated notes related to android application security for security professionals, bugbounty hunters, pentesters, reverse engineer, and redteamers.

License:MITStargazers:199Issues:7Issues:0

Bug-Hunting

A Collection of Notes, Methodologies, POCs and everything else related to Bug Hunting.

chronos

Wayback Machine OSINT Framework

Language:GoLicense:MITStargazers:132Issues:1Issues:3

raccoon

Salesforce object access auditor

Language:PythonLicense:AGPL-3.0Stargazers:104Issues:10Issues:0

ttt-ext

Chrome extension to aid in finding DOMXSS by simple taint analysis of string values.

burpsuite-project-file-parser

A Burp Suite Extension for parsing Project Files from the CLI.

wilson-cloud-respwnder

WILSON Cloud Respwnder is a Web Interaction Logger Sending Out Notifications with the ability to serve custom content in order to appropriately respond to client-issued requests.

hakcertstream

Basic implementation of certstream to print new subdomains and domains

diffJs

Script for monitoring changes in javascript files on WebApps for offensive reconnaissance.

ois-dos

Java Deserialization

Language:JavaLicense:MITStargazers:26Issues:6Issues:0

NoSQL_injection_stuff

Learn what is NoSQL injection and how to find them ?

License:MITStargazers:11Issues:1Issues:0

JSON-CSRF-PoC

JSON CSRF PoC

Language:HTMLStargazers:11Issues:1Issues:0