Skip to content
View himeda0's full-sized avatar

Block or report himeda0

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
79 stars written in Python
Clear filter

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 63,785 15,099 Updated Mar 7, 2025

⏬ Dumb downloader that scrapes the web

Python 55,279 9,733 Updated Jan 4, 2025

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Python 38,298 4,130 Updated Mar 9, 2025

Automatic SQL injection and database takeover tool

Python 33,535 5,810 Updated Feb 26, 2025

fsociety Hacking Tools Pack – A Penetration Testing Framework

Python 10,946 2,019 Updated Aug 8, 2024

You Know, For WEB Fuzzing ! 日站用的字典。

Python 7,759 2,458 Updated Nov 13, 2023

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

Python 5,973 720 Updated Mar 8, 2025

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

Python 5,552 953 Updated Dec 31, 2024

Automated All-in-One OS Command Injection Exploitation Tool.

Python 5,170 865 Updated Mar 7, 2025

A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference

Python 4,938 1,048 Updated Aug 6, 2023

Server-Side Template Injection and Code Injection Detection and Exploitation Tool

Python 3,888 681 Updated Apr 21, 2024

A python script that finds endpoints in JavaScript files

Python 3,850 613 Updated Apr 13, 2024

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

Python 3,408 742 Updated Nov 23, 2022

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

Python 3,407 351 Updated Feb 25, 2025

Automated NoSQL database enumeration and web application exploitation tool.

Python 3,019 587 Updated Jul 28, 2024

Detect and bypass web application firewalls and protection systems

Python 2,734 451 Updated Aug 11, 2024

Notes about attacking Jenkins servers

Python 2,035 336 Updated Jul 10, 2024

Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.

Python 1,766 261 Updated Oct 10, 2024

BBT - Bug Bounty Tools (examples💡)

Python 1,748 471 Updated Apr 5, 2024

A default credential scanner.

Python 1,473 250 Updated Dec 26, 2021

Obtain GraphQL API schema even if the introspection is disabled

Python 1,132 101 Updated Sep 28, 2024

Automatic SSTI detection tool with interactive interface

Python 1,001 127 Updated Oct 14, 2024

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automa…

Python 998 213 Updated Jan 13, 2025
Python 967 182 Updated Jan 14, 2025

Nuclei Templates Collection

Python 957 255 Updated May 7, 2024

A python script to scan for Apache Tomcat server vulnerabilities.

Python 818 98 Updated Feb 16, 2025

Open Redirection Analyzer

Python 768 106 Updated Mar 5, 2023

This repository contains all the supplement material for the book "The art of sub-domain enumeration"

Python 643 150 Updated Jan 30, 2019

参数 | 字典 collections

Python 625 193 Updated Apr 20, 2021

graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.

Python 608 73 Updated Nov 28, 2024
Next