streaak's repositories

keyhacks

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

pastebin-scraper

Pastebin-scraper tool leverages the API of https://psbdmp.ws/ to find emails/domains dumped in pastebin.

hacks

Small snippets and scripts which I use

Language:ShellStargazers:33Issues:3Issues:0

bugbounty-cheatsheet

A list of interesting payloads, tips and tricks for bug bounty hunters.

big-list-of-naughty-strings

The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.

Language:PythonLicense:MITStargazers:11Issues:2Issues:0

SSRF-Testing

SSRF (Server Side Request Forgery) testing resources

Language:PythonStargazers:11Issues:2Issues:0

github-search

Tools to perform basic search on GitHub.

Language:JavaScriptStargazers:5Issues:2Issues:0

hackpad

A web application hacker's toolbox. Base64 encoding/decoding, URL encoding/decoding, MD5/SHA1/SHA256/HMAC hashing, code deobfuscation, formatting, highlighting and much more.

Language:HTMLLicense:UnlicenseStargazers:5Issues:2Issues:0

hacks-1

A collection of hacks and one-off scripts

Language:GoStargazers:5Issues:2Issues:0

CRLF-Injection-Scanner

Command line tool for testing CRLF injection on list of domains.

Language:PythonStargazers:4Issues:2Issues:0

OSINT-Framework

OSINT Framework

Language:JavaScriptStargazers:3Issues:2Issues:0

oxml_xxe

A tool for embedding XXE/XML exploits into different filetypes

Language:RubyStargazers:3Issues:2Issues:0

retire.js

scanner detecting the use of JavaScript libraries with known vulnerabilities

Language:RoffLicense:NOASSERTIONStargazers:3Issues:2Issues:0

SubOver

A Powerful Subdomain Takeover Tool

Language:GoLicense:BSD-2-ClauseStargazers:3Issues:2Issues:0

CRLF-Injection-Payloads

Payloads for CRLF Injection

jwt_tool

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Language:PythonStargazers:2Issues:2Issues:0

APAC-Conferences

A community contributed consolidated list of InfoSec meetups in the Asia Pacific region.

License:GPL-3.0Stargazers:1Issues:2Issues:0

certasset

Takes ip range, Scan all open SSL Certs, Grab Cnames

Language:PythonStargazers:1Issues:2Issues:0

h1-212-ctf-solutions

A collection of the solutions people wrote for the H1-212 Capture The Flag event

heartbleed-poc

Test for SSL heartbeat vulnerability (CVE-2014-0160)

Language:RubyStargazers:1Issues:2Issues:0

ICU

An Extended, Modulair, Host Discovery Framework

Language:PythonStargazers:1Issues:2Issues:0

Java-Deserialization-Cheat-Sheet

The cheat sheet about Java Deserialization vulnerabilities

java_deserialization_exploits

A collection of Java Deserialization Exploits

Language:PythonStargazers:1Issues:2Issues:0

PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Language:HTMLStargazers:1Issues:2Issues:0

AndroidPinning

A standalone library project for certificate pinning on Android.

Language:JavaLicense:GPL-3.0Stargazers:0Issues:2Issues:0

assetnote-poc

(Proof of concept) push notifications for passive DNS data

Language:JavaScriptStargazers:0Issues:3Issues:0

gen_report

A quick, customizeable report generator for HackeOne. Increases productivity & efficiency.

Language:PHPStargazers:0Issues:3Issues:0

gifoeb

exploit for ImageMagick's uninitialized memory disclosure in gif coder

Language:PythonStargazers:0Issues:2Issues:0