A list of useful payloads and bypass for Web Application Security and Pentest/CTF
☆13Aug 26, 2021Updated 4 years ago
Alternatives and similar repositories for PayloadsAllTheThings
Users that are interested in PayloadsAllTheThings are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A simple vulnerable webapp created by PHP☆14Apr 18, 2025Updated last year
- Simple vulnerability labs that created using PHP and MySQL.☆16Dec 30, 2022Updated 3 years ago
- Aggregated wordlist pulled from commonly used tools for discovery, enumeration, fuzzing, and exploitation.☆11Dec 30, 2020Updated 5 years ago
- Spring4Shell reproduce☆11Apr 1, 2022Updated 4 years ago
- PHP lab to test captcha bypassing☆29Jan 8, 2024Updated 2 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Bash & Python scripts for daily life☆16Nov 27, 2018Updated 7 years ago
- CSbyGB - Gabrielle B's new Blog!☆23Jul 29, 2025Updated 11 months ago
- A small stuff of telegram bot for pentest and information gathering.☆11Oct 3, 2020Updated 5 years ago
- Links to VeteranSec Resources☆12May 18, 2020Updated 6 years ago
- Bot verifies a mobile phone number activity status by HLR-lookup. The request is processed by the communication operator without reaching…☆16Jan 25, 2022Updated 4 years ago
- ☆10Apr 30, 2022Updated 4 years ago
- Prototype-Pollution-Lab to chain the vulnerabilities between multiple accounts.☆13Sep 11, 2021Updated 4 years ago
- Python3 script to quickly get various information from a domain controller through his LDAP service.☆11Feb 23, 2022Updated 4 years ago
- ☆11Sep 30, 2020Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆10Sep 30, 2020Updated 5 years ago
- Automation for Open Threat Exchange☆24Mar 16, 2024Updated 2 years ago
- Simple website to guess API Key / OAuth Token☆48Aug 29, 2022Updated 3 years ago
- Random Tools for Bug Bounty☆150Oct 15, 2022Updated 3 years ago
- Config files for my GitHub profile.☆13Oct 9, 2022Updated 3 years ago
- A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the ac…☆19Apr 11, 2022Updated 4 years ago
- ☆13Mar 11, 2026Updated 3 months ago
- Extract parameters/paths from urls☆17Aug 2, 2020Updated 5 years ago
- ☆10May 30, 2021Updated 5 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- malware phylogeny for WSO web shell, Shellbot IRC bot and algorithm☆17May 24, 2022Updated 4 years ago
- It grep subdomains, email/username, build custom wordlist etc from gau results☆50Nov 4, 2022Updated 3 years ago
- A Python API to send messages via web-based free SMS providers☆18May 28, 2011Updated 15 years ago
- joomla com_xcloner exploit [Mass Autoexploiting script coded with python]☆13Apr 29, 2019Updated 7 years ago
- Assorted scripts I made for Red Teaming / Pen Testing☆14Jun 15, 2024Updated 2 years ago
- Manticore Ransomware Emulation - Educational Purpose Only!☆10Aug 2, 2020Updated 5 years ago
- Reference list for my Ransomware exploitation research. Lists current DLLs I have seen to date that some ransomware search for, which I h…☆11Jul 16, 2022Updated 3 years ago
- Do recon in single click☆22Jan 22, 2025Updated last year
- Detailed information about API key / OAuth token (Description, Request, Response, Regex, Example)☆296Sep 26, 2023Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- AutoExploiter Wordpress , Joomla , Drupal☆18Mar 27, 2018Updated 8 years ago
- This is a beginner level session to train you into using SSH more effectively. While pentesters may benefit (especially if they are plan…☆15Feb 9, 2019Updated 7 years ago
- Aplikasi untuk membangun NAT, DHCP Server, access log, cache web, port forwarding, VPN Server secara cepat termasuk konfigurasinya, pada …☆16May 15, 2022Updated 4 years ago
- ☆19Feb 9, 2021Updated 5 years ago
- ToyOS is a simple x86 OS that only accepts numeric values into the input stream and returns them to a standard out console.☆12Nov 27, 2025Updated 7 months ago
- Suricata rules that can detect a wide range of threats, including malware, exploits, and other malicious activity especially web applicat…☆62Apr 2, 2024Updated 2 years ago
- ☆14Mar 16, 2024Updated 2 years ago