bXSS by LewisArdern

bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.

created at Dec. 13, 2017, 11:49 p.m.

JavaScript

14 +0

518 +5

64 +0

GitHub
JShell by UltimateHackers

JShell - Get a JavaScript shell with XSS.

created at Feb. 26, 2018, 1:40 p.m.

Python

24 +0

511 +2

137 +0

GitHub
dns-rebind-toolkit by brannondorsey

A front-end JavaScript toolkit for creating DNS rebinding attacks.

created at June 19, 2018, 2:06 a.m.

JavaScript

24 +0

485 +0

93 +0

GitHub
dref by mwrlabs

DNS Rebinding Exploitation Framework

created at June 26, 2018, 10:09 a.m.

JavaScript

25 +0

481 +0

71 +0

GitHub
malware-jail by HynekPetrak

Sandbox for semi-automatic Javascript malware analysis, deobfuscation and payload extraction. Written for Node.js

created at Jan. 10, 2016, 10:41 p.m.

JavaScript

46 +0

460 +0

100 +0

GitHub
nano by UltimateHackers

Nano is a family of PHP web shells which are code golfed for stealth.

created at May 25, 2018, 3:17 p.m.

PHP

32 +0

435 +1

93 +0

GitHub
Webshell-Sniper by WangYihang

hammer Manage your website via terminal

created at July 24, 2017, 9:13 a.m.

Python

21 +0

420 +0

114 +0

GitHub
cssInjection by dxa4481

Stealing CSRF tokens with CSS injection (without iFrames)

created at Feb. 4, 2018, 4:09 a.m.

HTML

15 +0

318 +0

48 +0

GitHub
DVCS-Pillage by evilpacket

Pillage web accessible GIT, HG and BZR repositories

created at June 18, 2011, 8:04 p.m.

Shell

16 +0

314 +0

60 +0

GitHub
Reverse-Shell-Manager by WangYihang

hammer A multiple reverse shell session/client manager via terminal

created at Oct. 23, 2017, 1:41 a.m.

Python

8 +0

238 +0

66 +0

GitHub
JoomlaScan by drego85

A free software to find the components installed in Joomla CMS, built out of the ashes of Joomscan.

created at Feb. 11, 2016, 9:28 p.m.

Python

20 +0

215 +0

68 -1

GitHub
cefdebug by taviso

Minimal code to connect to a CEF debugger.

created at Oct. 3, 2019, 2:09 p.m.

C

7 +0

197 +0

19 +0

GitHub
GSDF by We5ter

A domain searcher named GoogleSSLdomainFinder - 基于谷歌SSL透明证书的子域名查询工具

created at Dec. 19, 2016, 4:58 p.m.

Python

7 +0

175 +0

57 +0

GitHub
ntlm_challenger by b17zr

Parse NTLM challenge messages over HTTP and SMB

created at Nov. 4, 2019, 10:27 p.m.

Python

4 +0

143 +0

25 +0

GitHub
IPObfuscator by OsandaMalith

A simple tool to convert the IP to a DWORD IP

created at April 30, 2016, 11:32 p.m.

C

9 +0

138 +0

46 +0

GitHub
pwngitmanager by allyshka

Git manager for pentesters

created at Feb. 25, 2016, 6:14 a.m.

Python

6 +0

107 +0

22 +0

GitHub
VWGen by qazbnm456

Vulnerable Web applications Generator

created at April 12, 2016, 4:06 p.m.

Python

7 +0

84 +0

18 +0

GitHub
BadLibrary by SecureSkyTechnology

vulnerable web application for training

created at Dec. 13, 2017, 6:43 a.m.

JavaScript

19 +0

58 +0

7 +0

GitHub
XSS.png by LucaBongiorni

A XSS mind map ;)

created at Jan. 16, 2016, 7:47 a.m.

Unknown languages

5 +0

56 +0

136 +0

GitHub
awesome-ctf-cheatsheet by uppusaikiran

CTF Cheatsheet

created at Feb. 11, 2020, 5:14 p.m.

Unknown languages

1 +0

50 +1

4 +0

GitHub