
of-CORS
Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

Python-based web security scanner that analyzes HTTP headers, SSL/TLS, DNS records, and common misconfigurations to generate a scored security report…

🦁 Python project to identify and scan for vulnerabilities related to the Joomla CMS project. It scans for common misconfigurations and public…

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

Adobe Experience Manager (AEM) hacking toolkit

Suite of programs meant to aid in bug hunting and security assessments

Supermicro IPMI/BMC Cleartext Password Scanner

The format of various s3 buckets is convert in one format. for bugbounty and security testing.

Retrieve AD accounts description and search for password in it


ActionScript Proof of Concept to perform cross-domain reads

泛微ecology OA系统接口存在数据库配置信息泄露漏洞

FAST WEB APPLICATION VULNERABILITY SCANNER written in python3

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

CVE-2023-28432 POC

ActiveMQ系列漏洞探测利用工具,包括ActiveMQ 默认口令漏洞及ActiveMQ任意文件写入漏洞(CVE-2016-3088),支持批量探测利用。

CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server