spaze / hashes
Magic hashes – PHP hash "collisions"
☆755Updated 3 weeks ago
Alternatives and similar repositories for hashes:
Users that are interested in hashes are comparing it to the libraries listed below
- A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.☆707Updated 11 months ago
- ☆798Updated 2 years ago
- List of XSS Vectors/Payloads☆1,223Updated 3 months ago
- Deriving RSA public keys from message-signature pairs☆310Updated 11 months ago
- Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.☆535Updated 4 months ago
- ☆674Updated 2 years ago
- My CTF journey since 2015. Stats, writeups, code snippets, notes, challenges.☆543Updated 2 weeks ago
- Simple DNS Rebinding Service☆649Updated 5 years ago
- This tool generates gopher link for exploiting SSRF and gaining RCE in various servers☆3,032Updated 2 years ago
- Perfect Blue's CTF Writeups☆674Updated 9 months ago
- Create tar/zip archives that can exploit directory traversal vulnerabilities☆997Updated 3 years ago
- detect stegano-hidden data in PNG & BMP☆1,397Updated last year
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆3,919Updated 11 months ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆861Updated 3 years ago
- Herramienta para evadir disable_functions y open_basedir☆415Updated last year
- A tool to dump a git repository from a website☆2,068Updated 4 months ago
- Simple websites vulnerable to Server Side Template Injections(SSTI)☆391Updated 2 years ago
- SSRF (Server Side Request Forgery) testing resources☆2,396Updated 6 months ago
- Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3☆1,939Updated last year
- Content-Type Research☆612Updated last year
- 🐛 A list of writeups from the Google VRP Bug Bounty program☆1,250Updated last month
- Everything needed for doing CTFs☆721Updated last year
- A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆1,138Updated last year
- Pwn stuff.☆1,772Updated 2 years ago
- PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.☆3,426Updated last week
- Client Side Prototype Pollution Scanner☆518Updated 2 years ago
- CTFNote is a collaborative tool aiming to help CTF teams to organise their work.☆546Updated this week
- ☆1,113Updated 2 months ago
- DotDotPwn - The Directory Traversal Fuzzer☆1,039Updated 2 years ago
- Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.☆1,614Updated 4 months ago