Shubs (infosec-au)

infosec-au

Geek Repo

Company:Assetnote

Location:Australia

Home Page:https://shubs.io

Github PK Tool:Github PK Tool

Shubs's starred repositories

dive

A tool for exploring each layer in a docker image

pure-sh-bible

📖 A collection of pure POSIX sh alternatives to external processes.

Language:ShellLicense:MITStargazers:6409Issues:94Issues:23

Recaf

The modern Java bytecode editor

Language:JavaLicense:MITStargazers:5819Issues:164Issues:565

apk-mitm

🤖 A CLI application that automatically prepares Android APK files for HTTPS inspection

Language:TypeScriptLicense:MITStargazers:3645Issues:44Issues:146

cariddi

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

Language:GoLicense:GPL-3.0Stargazers:1428Issues:13Issues:60

legba

A multiprotocol credentials bruteforcer / password sprayer and enumerator. 🥷

Language:RustLicense:NOASSERTIONStargazers:1333Issues:13Issues:44

jsluice

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Language:GoLicense:MITStargazers:1292Issues:14Issues:12

nuclei-wordfence-cve

The EXCLUSIVE Collection of 38,000+ Nuclei templates based on Wordfence intel. Daily updates for bulletproof WordPress security.

ShadowClone

Unleash the power of cloud

Language:PythonLicense:Apache-2.0Stargazers:686Issues:11Issues:55

rogue_mysql_server

A rouge mysql server supports reading files from most mysql libraries of multiple programming languages.

Language:GoLicense:MITStargazers:663Issues:6Issues:11

shortscan

An IIS short filename enumeration tool

Language:GoLicense:MITStargazers:652Issues:6Issues:14

noir

Attack surface detector that identifies endpoints by static analysis

Language:CrystalLicense:MITStargazers:518Issues:11Issues:84

aws-security-survival-kit

Bare minimum AWS Security Alerting and Configuration

Language:MakefileLicense:GPL-3.0Stargazers:441Issues:18Issues:17

curlshell

reverse shell using curl

Language:PythonStargazers:437Issues:6Issues:0

humanify

Deobfuscate Javascript code using ChatGPT

Language:TypeScriptLicense:MITStargazers:331Issues:10Issues:17

PIPE

Prompt Injection Primer for Engineers

cnext-exploits

Exploits for CNEXT (CVE-2024-2961), a buffer overflow in the glibc's iconv()

Language:PythonStargazers:317Issues:7Issues:0

route-detect

Find authentication (authn) and authorization (authz) security bugs in web application routes.

Language:PythonLicense:BSD-3-ClauseStargazers:239Issues:2Issues:16

wapalyzer

🌐 Identify the technologies powering any website. This is a fork of the now deleted Wappalyzer project by @AliasIO and community.

Language:JavaScriptLicense:GPL-3.0Stargazers:230Issues:6Issues:4

grepmarx

A source code static analysis platform for AppSec enthusiasts.

Language:PythonLicense:MITStargazers:194Issues:6Issues:8

HttpRemotingObjRefLeak

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

Language:PythonLicense:MITStargazers:75Issues:1Issues:1

EC2StepShell

EC2StepShell is an AWS post-exploitation tool for getting high privileges reverse shells in public or private EC2 instances.

Language:PythonLicense:MITStargazers:60Issues:1Issues:0

grepaddr

Use grepaddr to extract (grep) all kinds of addresses from stdin like URLs (incl. IPv4/IPv6), IP addresses & ranges (IPv4/IPv6), e-mail addresses, MAC addresses.

Language:PythonLicense:GPL-3.0Stargazers:60Issues:4Issues:1

Todesstern

A simple mutator engine which focuses on finding unknown classes of injection vulnerabilities

Language:PythonLicense:MITStargazers:59Issues:2Issues:0

pyyso

pyyso is a Python package that generate java serialized poc. Including CommonsCollections1-7, JDK7u21, JDK8u20, ldap for jndi, shiro-550, CommonsBeanutils1 no cc, JRMPClient, high version JDK Bypass, Fake MySQL for JDBC attack

Language:PythonLicense:MITStargazers:48Issues:2Issues:0

Zero-E

Automates the network enumeration process in a fire-and-forget manner, among many more functions. Zero effort, zero error network enumeration.

Language:ShellLicense:GPL-3.0Stargazers:42Issues:4Issues:0

nmapurls

Nmapurls parses Nmap xml reports from either piped input or command line arg and outputs a list of http(s) URL's to be used in an automation pipeline.

Language:GoLicense:GPL-3.0Stargazers:37Issues:1Issues:1
Language:C#License:NOASSERTIONStargazers:13Issues:0Issues:0

rate-limit-queue

An implementation of rate limited queues in Python, thread-safe, using only built-in components

Language:PythonStargazers:8Issues:1Issues:0