A list of useful payloads and bypass for Web Application Security and Pentest/CTF
☆13Aug 26, 2021Updated 4 years ago
Alternatives and similar repositories for PayloadsAllTheThings
Users that are interested in PayloadsAllTheThings are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A simple vulnerable webapp created by PHP☆14Apr 18, 2025Updated last year
- Simple vulnerability labs that created using PHP and MySQL.☆16Dec 30, 2022Updated 3 years ago
- Aggregated wordlist pulled from commonly used tools for discovery, enumeration, fuzzing, and exploitation.☆11Dec 30, 2020Updated 5 years ago
- Spring4Shell reproduce☆11Apr 1, 2022Updated 4 years ago
- PHP lab to test captcha bypassing☆30Jan 8, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Bash & Python scripts for daily life☆16Nov 27, 2018Updated 7 years ago
- CSbyGB - Gabrielle B's new Blog!☆23Jul 29, 2025Updated 9 months ago
- Links to VeteranSec Resources☆12May 18, 2020Updated 6 years ago
- Template to detect some malware☆14Aug 7, 2023Updated 2 years ago
- Bot verifies a mobile phone number activity status by HLR-lookup. The request is processed by the communication operator without reaching…☆16Jan 25, 2022Updated 4 years ago
- Prototype-Pollution-Lab to chain the vulnerabilities between multiple accounts.☆13Sep 11, 2021Updated 4 years ago
- Python3 script to quickly get various information from a domain controller through his LDAP service.☆11Feb 23, 2022Updated 4 years ago
- ☆10Sep 30, 2020Updated 5 years ago
- Automation for Open Threat Exchange☆24Mar 16, 2024Updated 2 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Simple website to guess API Key / OAuth Token☆49Aug 29, 2022Updated 3 years ago
- Config files for my GitHub profile.☆13Oct 9, 2022Updated 3 years ago
- ☆13Mar 11, 2026Updated 2 months ago
- A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the ac…☆19Apr 11, 2022Updated 4 years ago
- Extract parameters/paths from urls☆17Aug 2, 2020Updated 5 years ago
- Go script for bypassing 403 forbidden☆162Aug 6, 2021Updated 4 years ago
- ☆10May 30, 2021Updated 4 years ago
- It grep subdomains, email/username, build custom wordlist etc from gau results☆50Nov 4, 2022Updated 3 years ago
- A Python API to send messages via web-based free SMS providers☆18May 28, 2011Updated 14 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Assorted scripts I made for Red Teaming / Pen Testing☆14Jun 15, 2024Updated last year
- Manticore Ransomware Emulation - Educational Purpose Only!☆10Aug 2, 2020Updated 5 years ago
- Do recon in single click☆21Jan 22, 2025Updated last year
- Detailed information about API key / OAuth token (Description, Request, Response, Regex, Example)☆294Sep 26, 2023Updated 2 years ago
- A Proof-Of-Concept for the recently found CVE-2021-44228 vulnerability.☆11Nov 26, 2022Updated 3 years ago
- ☆14Feb 16, 2023Updated 3 years ago
- This is a beginner level session to train you into using SSH more effectively. While pentesters may benefit (especially if they are plan…☆15Feb 9, 2019Updated 7 years ago
- ☆18Feb 9, 2021Updated 5 years ago
- Suricata rules that can detect a wide range of threats, including malware, exploits, and other malicious activity especially web applicat…☆62Apr 2, 2024Updated 2 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- ToyOS is a simple x86 OS that only accepts numeric values into the input stream and returns them to a standard out console.☆12Nov 27, 2025Updated 5 months ago
- ☆12Dec 26, 2021Updated 4 years ago
- A small string masking library in javascript☆12Dec 15, 2023Updated 2 years ago
- A simple Mac-Address Sniffer based on tshark☆12Dec 27, 2018Updated 7 years ago
- ☆15Dec 3, 2020Updated 5 years ago
- A collection oneliner scripts for bug bounty☆185Mar 21, 2024Updated 2 years ago
- A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.☆19Jul 28, 2022Updated 3 years ago