Bruno - Zeroc00I's Projects
Fast DNS resolver written in Rust.
Free, libre, effective, and data-driven wordlists for all!
sometimes you get an jira instance and you want to test all endpoints , it's really hard to do it manually , this tool will help you to reduce time and test all endpoint for you
Scrapts Scrapts Scrapts
collection of testing scripts
A laboratory for learning secure web and mobile development in a practical manner.
A place to raise issues with the WHATWG Steering Group
:robot: Telegram bot that executes commands and sends the live output
Command line tool to query AST nodes in JavaScript source files.
Get ports,vulnerabilities,informations,banners,..etc for any IP with Shodan (no apikey! no rate-limit!)
Search Google/Bing/DuckDuckGo/Yandex/Yahoo for a search term with different websites. A default list is already provided.
Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3
Automated pentest framework for offensive security experts
SocialPwned is an OSINT tool that allows to get the emails, from a target, published in social networks such as Instagram, Linkedin and Twitter to find possible credentials leaks in PwnDB.
Apache Solr SSRF(CVE-2021-27905)
A MongoDB importer and API for Project Sonars DNS datasets
Multi-threaded socks proxy checker written in Go!
Black Falcon
SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list
An SSRF detector tool written in golang. I have fixed some errors and added some more payloads to it. But the tool credits go to z0idsec.
Subdomain Enumeration Wordlist. 8956437 unique words. Updated.
Utilizando Terraform para Criar maquinas na AWS
A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
A collection of tiny XSS Payloads that can be used in different contexts.
Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins :arrow_up: :skull_and_crossbones:
An HTTP over TURN/STUN proxy
A GoHorse Bash Tool to extract last tweet from monitored users and send the response into a telegram channel, but without any authentication twitter proccess (Oauth or build an app), just using Pub data.