
oproxy
Open-source MITM proxy to intercept, inspect, and mock network traffic.

Open-source MITM proxy to intercept, inspect, and mock network traffic.

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

Extract subdomains from SSL certificates in HTTPS sites.

Multi-threaded router fingerprinting tool that identifies web-exposed network devices by analyzing HTTP responses, headers, and favicon hashes for…


HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.

Proof of Concept exploit for CVE-2026-46368 — authenticated root command injection in OpenWrt luci-app-https-dns-proxy (EDB-52521)

Trusted localhost HTTPS — local CA, /etc/hosts, mDNS LAN sharing, reverse proxy. Maps https://name.local → localhost:port

:lock: Memorable site for testing clients against bad SSL configs.


PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.

Covert C2 framework using QR codes for indirect command execution and result retrieval via HTTP/S, designed for stealthy penetration testing and red…


Generates randomized, lint-validated C2 malleable profiles for Cobalt Strike, automating HTTP/S, DNS, SMB, and SSH beacon configuration with…


Unauthenticated RCE via Webmin Backdoor (CVE-2019–15107)

CVE-2023-3452 exploit for WordPress Canto plugin RCE, HTTPS support included