karvashy's starred repositories

chunkloader

A chrome/Firefox extension to retrieve and load react javascript chunks all at once for a wide range of javascript techs

Language:JavaScriptStargazers:60Issues:0Issues:0

repolist

Generate wordlists from Github repositories

Language:PythonStargazers:92Issues:0Issues:0

dmut

A tool to perform permutations, mutations and alteration of subdomains in golang.

Language:GoLicense:MITStargazers:155Issues:0Issues:0

LLM101n

LLM101n: Let's build a Storyteller

Stargazers:28158Issues:0Issues:0

wscan

Wscan is a web security scanner that focuses on web security, dedicated to making web security accessible to everyone.

Language:GoLicense:NOASSERTIONStargazers:511Issues:0Issues:0

misconfig-mapper

Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets!

Language:GoLicense:MITStargazers:329Issues:0Issues:0

BucketLoot

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text.

Language:GoLicense:MITStargazers:370Issues:0Issues:0
Language:PythonLicense:MITStargazers:906Issues:0Issues:0

JS-Tap

JavaScript payload and supporting software to be used as XSS payload or post exploitation implant to monitor users as they use the targeted application. Also includes a C2 for executing custom JavaScript payloads in clients, and a "mimic" feature that automatically generates custom payloads.

Language:JavaScriptLicense:UnlicenseStargazers:327Issues:0Issues:0

smugglefuzz

A rapid HTTP downgrade smuggling scanner written in Go.

Language:GoLicense:MITStargazers:242Issues:0Issues:0

domlogger-configs

Useful configurations for the DomLogger++ extension

Stargazers:22Issues:0Issues:0

domloggerpp

A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.

Language:JavaScriptLicense:GPL-3.0Stargazers:391Issues:0Issues:0

fuzzing-templates

Community curated list of nuclei templates for finding "unknown" security vulnerabilities.

License:MITStargazers:24Issues:0Issues:0

objection

📱 objection - runtime mobile exploration

Language:PythonLicense:GPL-3.0Stargazers:7342Issues:0Issues:0

burpsuite-project-file-parser

A Burp Suite Extension for parsing Project Files from the CLI.

Language:JavaStargazers:82Issues:0Issues:0

guidtool

A tool to inspect and attack version 1 GUIDs

Language:PythonStargazers:205Issues:0Issues:0

cdn-proxy

Bypass CDN and WAF restrictions using CDN re-fronting.

Language:PythonStargazers:231Issues:0Issues:0

freebind

IPv6 address rate limiting evasion tool (that also supports IPv4)

Language:CLicense:GPL-3.0Stargazers:209Issues:0Issues:0
Language:PythonLicense:Apache-2.0Stargazers:222Issues:0Issues:0

cookiemonster

🍪 CookieMonster helps you detect and abuse vulnerable implementations of stateless sessions.

Language:GoLicense:MITStargazers:810Issues:0Issues:0

can-i-take-over-dns

"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.

Stargazers:958Issues:0Issues:0

weirdAAL

WeirdAAL (AWS Attack Library)

Language:PythonStargazers:773Issues:0Issues:0

server-side-prototype-pollution

A collection of Server-Side Prototype Pollution gadgets and exploits

Language:JavaScriptLicense:MITStargazers:124Issues:0Issues:0

postMessage-tracker

A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon

License:MITStargazers:3Issues:0Issues:0

AIAIAI

An Incredibly Annoying, Insufferable Authentication Implementation

Language:PythonStargazers:30Issues:0Issues:0

sic

A tool to perform Sequential Import Chaining

Language:RustLicense:MITStargazers:249Issues:0Issues:0

ResourceOverride

An extension to help you gain full control of any website by redirecting traffic, replacing, editing, or inserting new content.

Language:JavaScriptLicense:MITStargazers:467Issues:0Issues:0

singularity

A DNS rebinding attack framework.

Language:JavaScriptLicense:MITStargazers:1016Issues:0Issues:0

transformers.js

State-of-the-art Machine Learning for the web. Run 🤗 Transformers directly in your browser, with no need for a server!

Language:JavaScriptLicense:Apache-2.0Stargazers:10934Issues:0Issues:0

cloudfox

Automating situational awareness for cloud penetration tests.

Language:GoLicense:MITStargazers:1894Issues:0Issues:0