spaze / hashesLinks
Magic hashes – PHP hash "collisions"
☆818Updated 10 months ago
Alternatives and similar repositories for hashes
Users that are interested in hashes are comparing it to the libraries listed below
Sorting:
- A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.☆740Updated last year
- Simple DNS Rebinding Service☆721Updated 6 years ago
- Create tar/zip archives that can exploit directory traversal vulnerabilities☆1,037Updated 4 years ago
- Deriving RSA public keys from message-signature pairs☆370Updated last week
- Herramienta para evadir disable_functions y open_basedir☆487Updated 2 years ago
- ☆1,177Updated last year
- Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.☆621Updated last year
- ☆984Updated 3 years ago
- CTFNote is a collaborative tool aiming to help CTF teams to organise their work.☆591Updated this week
- List of XSS Vectors/Payloads☆1,358Updated 3 weeks ago
- A semi-interactive PHP shell compressed into a single file.☆1,029Updated 7 years ago
- Perfect Blue's CTF Writeups☆694Updated last year
- ☆1,185Updated 8 years ago
- PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.☆3,723Updated 4 months ago
- Yet another Stego Tool☆401Updated 2 years ago
- Prototype Pollution and useful Script Gadgets☆1,577Updated 2 years ago
- Files + Writeups for DownUnderCTF 2022 Challenges☆251Updated 3 years ago
- A DNS rebinding attack framework.☆1,254Updated 2 months ago
- Client Side Prototype Pollution Scanner☆524Updated 3 years ago
- Content-Type Research☆655Updated 7 months ago
- ☆694Updated 3 years ago
- My CTF journey since 2015. Stats, writeups, code snippets, notes, challenges.☆572Updated 3 months ago
- Simple websites vulnerable to Server Side Template Injections(SSTI)☆415Updated 2 years ago
- ☆709Updated last year
- Writeups for various CTFs☆673Updated last month
- Predict python's random module generated values.☆432Updated last year
- Issues with WebSocket reverse proxying allowing to smuggle HTTP requests☆388Updated last year
- A script to automatically install Peda+pwndbg+GEF plugins for gdb☆474Updated 2 years ago
- Automated script for performing Padding Oracle attacks☆803Updated last year
- A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆1,278Updated 2 years ago