
hacker-roadmap
A collection of hacking tools, resources and references to practice ethical hacking.

A collection of hacking tools, resources and references to practice ethical hacking.

Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction.

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

Rewe API reverse engineering in Go

An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.

CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection

Tips on how to write exploit scripts (faster!)

Test authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.

Indicator of Compromise Scanner for CVE-2019-19781

Go tool and Nuclei template for testing James Kettle's (CVE-2025-32094) HTTP/1.1 must die: the desync endgame

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

High-speed Burp Suite extension for sending large volumes of HTTP requests with a custom stack, Python-based attack configuration, and advanced…

Fast HTTP enumerator

Web-based check for Windows privesc vulnerabilities

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of…

Curated penetration testing wiki with daily-updated techniques, scripts, and checklists for reconnaissance, web, cloud, mobile, and…

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…