There are 1 repository under vapt topic.
A Python3 based C2 server to make life of red teamer a bit easier. The payload is capable to bypass all the known antiviruses and endpoints.
eLearnSecurity Junior Penetration Tester (eJPT) v2 Notes
This is my personal repo, which includes bug bounty tips, a collection of tools, one-liners, and other resources I personally prefer while hunting. It is still under development, so feel free to contribute.
A simple Dockerfile to build an image starting from the latest official one of Kali Linux and including some useful tools.
The iOS Buster is a groundbreaking penetration testing tool for iOS, capable of performing both static and dynamic testing. It provides detailed reports, including STR, highlighting discovered vulnerabilities. It serves as a valuable addition to MobSF.
This is Web Application Penetration Testing Report made for everybody who wanted a glance of how to make a professional report for pentetring purpose. The penetration testing has been done in a sample testable website.
All things Cybersecurity!
Physical penetration testing is a critical aspect of security assessment that involves simulating real-world attacks to evaluate the effectiveness of physical security controls.
Project Davinci, led by Government Engineering College (GEC) Thrissur, focuses on "Secure-KTU," enhancing the security of the KTU website. The project assesses vulnerabilities per NCIIPC RVDP standards, addressing threats like data breaches and unauthorized access, ensuring safer online services.
CyberSecurity Interview Questions
Postman-API-Count is a tool that simplifies the extraction and analysis of APIs from Postman collections. It allows users to extract APIs based on specific HTTP methods, identify APIs without any defined methods, and retrieve the total count of APIs in a collection. This tool is beneficial for developers and testers working with Postman collections
SCOPE [Subdomain Cache Observation, Poisoning & Evaluation] is a powerful tool designed to help you find and test vulnerabilities in subdomains that might be exposed to cache poisoning attacks. If a website isn't properly handling cache, it could lead to security issues where malicious content gets stored and served to users.
XML-Hydra is a tool to bruteforce user passwords via public facing XML-RPC interface in a Wordpress application.
Cloud penetration testing methods, phases, lifecycle & tools
PYTHA-SHELL is an educational cybersecurity tool featuring an RCE mode. It offers practical examples and demonstrations to help students understand various attacks and vulnerabilities in a controlled environment. PYTHA-SHELL provides hands-on experience with real-world security risks making it a valuable resource for learning and teaching
Parrot OS : Vulnerability Analysis in Parrot Linux is a mobile app that contains tutorials, commands and live screenshots to help aspiring learners in using Parrot Linux Operating System.
Apache Superset - Authentication Bypass
This is a tool used by several security researchers to find Open Redirect Bug
This report presents the findings and recommendations from a security assessment conducted on the Home of Acunetix Art Web Application.
CVE-2020-27838 - KeyCloak - Information Exposure
Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal
WordPress Contact Form 7 - Unrestricted File Upload
Set up a secure Azure network with an OpenVas Vulnerability Scanner VM.
This is a sample Vulnerability Assessment and Penetration Testing for the website http://testphp.vulnweb.com/
Vulnhub's machines reports
A sample report of Vulnerability Assesment
A collection of scripts and commands for assessing and securing IT environments.
Web Security Audit
It is an automated host header scanning and attacking tool.
A curated resource for mobile security testing based on OWASP MASTG. Includes notes, tools, and practical examples for pentesters and developers.
This script automates the installation of essential Android security tools and application for mobile application testing