cyal1's repositories
BurpCollector
通过BurpSuite来构建自己的爆破字典,可以通过字典爆破来发现隐藏资产。对 https://github.com/TEag1e/BurpCollector 的增强,通过熵(混乱程度的度量)计算去除混乱的数据。
besticon
Favicon service written in Go
blind-ssrf-chains
An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability
bugbounty-cheatsheet
A list of interesting payloads, tips and tricks for bug bounty hunters.
c-jwt-cracker
JWT brute force cracker written in C
can-i-take-over-xyz
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
FavFreak
Making Favicon.ico based Recon Great again !
Gibberish-Detector
A small program to detect gibberish using a Markov Chain
GitTools
A repository with 3 tools for pwn'ing websites with .git repositories available
gogs
Gogs is a painless self-hosted Git service
haxel0rds
Some private tools i decided to release for public.
joshspicer.github.io
My "Internet Home" (aka blog)
knock
Simple python port knocking client
laravel-exploits
Exploit for CVE-2021-3129
My-Presentation-Slides
Collections of Orange Tsai's public presentation slides.
oxml_xxe
A tool for embedding XXE/XML exploits into different filetypes
pdd_3years
我在拼多多的三年,以及网站崩溃时候的日志文件
PwnLnX
An advanced multi-threaded, multi-client python reverse shell for hacking linux systems. There's still more work to do so feel free to help out with the development. Disclaimer: This reverse shell should only be used in the lawful, remote administration of authorized systems. Accessing a computer network without authorization or permission is illegal.
rogue-jndi
A malicious LDAP server for JNDI injection attacks
seeyonAjaxGetshell
致远OA seeyon未授权漏洞批量getshell
shuji
Reverse engineering JavaScript and CSS sources from sourcemaps
SSRF-Testing
SSRF (Server Side Request Forgery) testing resources
Stowaway
👻Stowaway -- Multi-hop Proxy Tool for pentesters
timeless-timing-attacks
A Python implementation that facilitates finding timeless timing attack vulnerabilities.
topNameIntruder
chinese name top 500
truffleHog
Searches through git repositories for high entropy strings and secrets, digging deep into commit history
xray
一款完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档
Xray_onekey
Xray 基于 Nginx 的 VLESS + XTLS 一键安装脚本
ysoserial.net
Deserialization payload generator for a variety of .NET formatters