icytrues's starred repositories

fimap

fimap is a little python tool which can find, prepare, audit, exploit and even google automatically for local and remote file inclusion bugs in webapps.

Language:PythonLicense:GPL-2.0Stargazers:508Issues:0Issues:0

FDsploit

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

Language:PythonLicense:GPL-3.0Stargazers:262Issues:0Issues:0

LFISuite

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Language:PythonLicense:GPL-3.0Stargazers:1648Issues:0Issues:0

liffy

Local file inclusion exploitation tool

Language:PythonLicense:GPL-3.0Stargazers:755Issues:0Issues:0

github-search

A collection of tools to perform searches on GitHub.

Language:PythonLicense:MITStargazers:1312Issues:0Issues:0

fav-up

IP lookup by favicon using Shodan

Language:PythonLicense:MITStargazers:1043Issues:0Issues:0

commonspeak2-wordlists

Wordlists that have been compiled using Commonspeak2. This repo is updated every time new wordlists are generated.

License:Apache-2.0Stargazers:512Issues:0Issues:0

ssrf-sheriff

A simple SSRF-testing sheriff written in Go

Language:GoLicense:MITStargazers:310Issues:0Issues:0

MyPapers

Repository for hosting my research papers

Language:PythonLicense:NOASSERTIONStargazers:496Issues:0Issues:0

CheatSheetSeries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Language:PythonLicense:CC-BY-SA-4.0Stargazers:27366Issues:0Issues:0

Syborg

Recursive DNS Subdomain Enumerator with dead-end avoidance system (BETA)

Language:PythonStargazers:142Issues:0Issues:0

assetnote-poc

(Proof of concept) push notifications for passive DNS data

Language:JavaScriptStargazers:7Issues:0Issues:0

snuffleupagus

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Language:PHPLicense:LGPL-3.0Stargazers:752Issues:0Issues:0

pwnagotchi

(⌐■_■) - Deep Reinforcement Learning instrumenting bettercap for WiFi pwning.

Language:PythonLicense:NOASSERTIONStargazers:7473Issues:0Issues:0
Language:JavaLicense:NOASSERTIONStargazers:1187Issues:0Issues:0

keyhacks

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

Stargazers:4780Issues:0Issues:0

xmlrpc-bruteforcer

An XMLRPC brute forcer targeting Wordpress written in Python 3. (DISCONTINUED)

Language:PythonStargazers:63Issues:0Issues:0

jwt_tool

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Language:PythonLicense:GPL-3.0Stargazers:5231Issues:0Issues:0

PHP-vulnerability-audit-cheatsheet

This will assist you in the finding of potentially vulnerable PHP code. Each type of grep command is categorized in the type of vulnerabilities you generally find with that function.

License:NOASSERTIONStargazers:345Issues:0Issues:0

domdig

DOM XSS scanner for Single Page Applications

Language:JavaScriptLicense:GPL-3.0Stargazers:388Issues:0Issues:0

fuxploider

File upload vulnerability scanner and exploitation tool.

Language:PythonLicense:GPL-3.0Stargazers:3012Issues:0Issues:0

altdns

Generates permutations, alterations and mutations of subdomains and then resolves them

Language:PythonLicense:Apache-2.0Stargazers:2284Issues:0Issues:0

Arjun

HTTP parameter discovery suite.

Language:PythonLicense:AGPL-3.0Stargazers:5063Issues:0Issues:0

httprobe

Take a list of domains and probe for working HTTP and HTTPS servers

Language:GoLicense:MITStargazers:2801Issues:0Issues:0

pq

Pure Go Postgres driver for database/sql

Language:GoLicense:MITStargazers:8960Issues:0Issues:0

hacks

A collection of hacks and one-off scripts

Language:GoStargazers:2111Issues:0Issues:0

meg

Fetch many paths for many hosts - without killing the hosts

Language:GoLicense:MITStargazers:1578Issues:0Issues:0
Language:JavaScriptLicense:NOASSERTIONStargazers:314Issues:0Issues:0

Platypus

:hammer: A modern multiple reverse shell sessions manager written in go

Language:GoLicense:LGPL-3.0Stargazers:1488Issues:0Issues:0

chashell

Chashell is a Go reverse shell that communicates over DNS. It can be used to bypass firewalls or tightly restricted networks.

Language:GoStargazers:1044Issues:0Issues:0