
Hacking-Tools
A curated list of penetration testing and ethical hacking tools, organized by category. This compilation includes tools from Kali Linux and other…

A curated list of penetration testing and ethical hacking tools, organized by category. This compilation includes tools from Kali Linux and other…

CLI to download websites' actual JS/CSS/assets (not flattened HTML)

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

A cloud native Identity & Access Proxy / API (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s)…

Deserialization payload generator for a variety of .NET formatters

A library for detecting known secrets across many web frameworks

The most powerful CRLF injection (HTTP Response Splitting) scanner.

FreePBX 未认证SQL注入导致远程代码执行,FreePBX 15 (低于 15.0.66)、16 (低于 16.0.89)、17 (低于 17.0.3)。该漏洞位于商业化“endpoint”模块中,因对用户输入过滤不严,允许未认证的攻击者绕过管理员权限,执行SQL注入,并最终实现远程代码执行

More private by default Firefox ESR. Fork of ghostery.

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

Chrome extension for fast web fuzzing to discover hidden files and directories during penetration testing and vulnerability analysis.

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Web application security scanner created by lcamtuf for google - Unofficial Mirror

Tool for assessing on-premises Microsoft servers authentication such as ADFS, Skype, Exchange, and RDWeb

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Source code for the book "Black Hat Python" by Justin Seitz. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards…

Detection for CVE-2025-53072 + CVE-2025-62481