Voorivex's starred repositories

PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Language:PythonLicense:MITStargazers:57431Issues:1806Issues:0

awesome-pentest

A collection of awesome penetration testing resources, tools and other shiny things

vulhub

Pre-Built Vulnerable Environments Based on Docker-Compose

Language:DockerfileLicense:MITStargazers:16576Issues:569Issues:175

dirsearch

Web path scanner

Resources-for-Beginner-Bug-Bounty-Hunters

A list of resources for those interested in getting started in bug bounties

xray

一款完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档

Language:VueLicense:NOASSERTIONStargazers:9763Issues:207Issues:443

PoC-in-GitHub

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

Awesome-WAF

🔥 Web-application firewalls (WAFs) from security standpoint.

Language:PythonLicense:Apache-2.0Stargazers:5985Issues:258Issues:6

Modlishka

Modlishka. Reverse Proxy.

Language:GoLicense:NOASSERTIONStargazers:4692Issues:136Issues:286

AwesomeXSS

Awesome XSS stuff

Language:JavaScriptLicense:MITStargazers:4667Issues:240Issues:13

learnjavabug

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Language:JavaLicense:MITStargazers:2528Issues:73Issues:6

awesome-oneliner-bugbounty

A collection of awesome one-liner scripts especially for bug bounty tips.

CloudFlair

🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.

jexboss

JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool

Language:PythonLicense:NOASSERTIONStargazers:2373Issues:95Issues:61

ParamSpider

Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing

Language:PythonLicense:MITStargazers:2250Issues:37Issues:90

frida-snippets

Hand-crafted Frida examples

31-days-of-API-Security-Tips

This challenge is Inon Shkedy's 31 days API Security Tips.

Android-Reports-and-Resources

A big list of Android Hackerone disclosed reports and other resources.

awesome-jenkins-rce-2019

There is no pre-auth RCE in Jenkins since May 2017, but this is the one!

Language:PythonLicense:BSD-3-ClauseStargazers:458Issues:5Issues:17

DoHC2

DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH).

h1domains

HackerOne "in scope" domains

tor-router

A tool that allows you to make TOR your default gateway and send all internet connections under TOR (as transparent proxy) to increase privacy/anonymity without extra unnecessary code.

Language:ShellLicense:GPL-3.0Stargazers:268Issues:11Issues:8

pybotnet

PyBotNet: A High-Level Remote Control Framework for Python with Telegram Integration

Language:PythonLicense:LGPL-2.1Stargazers:240Issues:8Issues:26

CryptOMG

CryptOMG is a configurable CTF style test bed that highlights common flaws in cryptographic implementations.

Language:PHPLicense:GPL-3.0Stargazers:189Issues:19Issues:0

bruteforce-http-auth

Bruteforce HTTP Authentication

Slides

Slides from various talks that I've given over the years

dfunc-bypasser

This tool is for letting you know how strong your disable_functions is and how you can bypass that.

reconmaster

ReconMaster contest - scripts used and a write-up

Language:ShellStargazers:78Issues:2Issues:0

AttackingAndDefendingTheGCPMetadataAPI

This repo gives an overview of some GCP metadata API attack and defend patterns

License:GPL-2.0Stargazers:77Issues:4Issues:0