
ninjasworkout
Deliberately vulnerable Node.js web application containing 19+ security bugs (XSS, SSRF, Prototype Pollution, RCE) for hands-on penetration testing…

Deliberately vulnerable Node.js web application containing 19+ security bugs (XSS, SSRF, Prototype Pollution, RCE) for hands-on penetration testing…

A script for automatize boolean-based blind SQL injections (MVP).

Framework for identifying and exploiting out-of-band (OOB) application vulnerabilities with a custom DNS/token server, Burp Suite extension, and…

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies

The Swiss Army knife for automated Web Application Testing

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

ChatGPT Plus/Team/Pro 订阅协议端到端重放工具集 · hCaptcha 视觉求解器 · 反欺诈机制实证研究 / End-to-end protocol replay toolkit for ChatGPT Plus/Team/Pro subscription with…

🤖 A CLI application that automatically prepares Android APK files for HTTPS inspection

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

Stage two containers

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…


Repository contains description for CVE-2023-35793

POC CVE-2018-14714


PoC of HTTP Request Smuggling in nodejs (CVE-2020-8287)

PoC for CVE-2020-8165