A little collection of fun and creative proof of concepts to demonstrate the potential impact of a security vulnerability.
☆166Nov 6, 2019Updated 6 years ago
Alternatives and similar repositories for proof-of-concepts
Users that are interested in proof-of-concepts are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An OSINT tool to find contacts in order to report security vulnerabilities.☆268Jan 27, 2020Updated 6 years ago
- Bug Bounty Guide is a launchpad for bug bounty programs and bug bounty hunters.☆473Nov 10, 2022Updated 3 years ago
- This document proposes a way of standardising the structure, language, and grammar used in security policies.☆26Jan 29, 2018Updated 8 years ago
- A formula to calculate bounty amounts.☆15Dec 2, 2017Updated 8 years ago
- Some random scripts. Just trying to be like the cool kids.☆100Jul 1, 2018Updated 8 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- List of bug bounty programs of companies/organisations in Switzerland☆13Oct 28, 2021Updated 4 years ago
- Guidelines for writing secure code for Python developers.☆22Apr 23, 2017Updated 9 years ago
- A collection of response templates for invalid bug bounty reports.☆90Feb 26, 2018Updated 8 years ago
- Burp Suite extension for JAX-RS☆66Mar 17, 2017Updated 9 years ago
- A list of interesting payloads, tips and tricks for bug bounty hunters.☆6,514Sep 14, 2023Updated 2 years ago
- Automated reconnaissance wrapper — TomNomNom's meg on steroids. [DEPRECATED]☆304Oct 14, 2018Updated 7 years ago
- A cheat sheet for pentesters and researchers about vulnerabilities in well-known monitoring systems.☆167Jun 10, 2021Updated 5 years ago
- My recon script☆50Dec 23, 2019Updated 6 years ago
- A static website template for security pages.☆54Jul 19, 2025Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Scans crossdomain.xml policies for expired domain names.☆26Aug 4, 2015Updated 10 years ago
- Extract Juniper firewall usernames and hashes and put into a John the Ripper format for cracking☆13Jul 4, 2014Updated 12 years ago
- ISR-sqlget It's a blind SQL injection tool developed in Perl.☆14Apr 26, 2013Updated 13 years ago
- Pentest scripts for abuse Bash on Windows (Cygwin/WSL) - HackLu 2018☆45May 29, 2019Updated 7 years ago
- A tool to generate media files with malicious metadata☆129Feb 2, 2019Updated 7 years ago
- A CLI tool to interact with hackerone.com. This was my submission for HackerOne's Summer 2018 Hack Day.☆41Aug 2, 2018Updated 7 years ago
- Reconnaissance tool which scans javascript files for subdomains and then iterates over all javascript files hosted on subsequent subdomai…☆224Jul 10, 2020Updated 6 years ago
- The Bug Bounty Wiki☆173Oct 31, 2018Updated 7 years ago
- "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.☆5,755Feb 8, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A python script that filters, checks the validity, generates clickable link(s) of subdomain(s), and reports their status☆89Oct 29, 2020Updated 5 years ago
- A small tool that extracts relative URLs from a file.☆771Sep 23, 2020Updated 5 years ago
- Literally spray blind xss payloads everywhere.☆26Feb 22, 2022Updated 4 years ago
- This repository created for personal use and added tools from my latest blog post.☆352Dec 7, 2022Updated 3 years ago
- A highly configurable Framework for easy automated web scanning☆383Jul 13, 2020Updated 6 years ago
- Misc. Public Reports of Penetration Testing and Security Audits.☆37Jan 8, 2021Updated 5 years ago
- Simple tool to test for SSRF/OOB HTTP Read within the Path of a request☆30Aug 2, 2019Updated 6 years ago
- BurpSuite dockerized☆11Mar 2, 2018Updated 8 years ago
- ☆16Oct 24, 2018Updated 7 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- ☆278Oct 19, 2021Updated 4 years ago
- A script that monitors and extracts requested URLs and clients connected to the service by exploiting publicly accessible Apache server-s…☆444Sep 19, 2021Updated 4 years ago
- CVE-2020-3452 exploit☆24Aug 1, 2020Updated 5 years ago
- My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.☆924Apr 22, 2026Updated 2 months ago
- Quickly generate context-specific wordlists for content discovery from lists of URLs or paths☆239May 4, 2022Updated 4 years ago
- DNS Takeover tool written in Go☆2,101Jul 3, 2026Updated 2 weeks ago
- Quick and dirty scripts that don't really belong in a larger project☆34Oct 22, 2025Updated 8 months ago