Magic hashes – PHP hash "collisions"
☆829Mar 23, 2025Updated last year
Alternatives and similar repositories for hashes
Users that are interested in hashes are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.☆3,784Sep 29, 2025Updated 6 months ago
- Web CTF CheatSheet 🐈☆2,951Oct 28, 2025Updated 5 months ago
- ☆1,014Jan 23, 2023Updated 3 years ago
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆4,140Apr 21, 2024Updated last year
- Prototype Pollution and useful Script Gadgets☆1,607Jan 27, 2024Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A repository with 3 tools for pwn'ing websites with .git repositories available☆4,132Jun 14, 2023Updated 2 years ago
- Deserialization payload generator for a variety of .NET formatters☆3,706Dec 23, 2024Updated last year
- A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.☆755May 6, 2024Updated last year
- A toolkit for testing, tweaking and cracking JSON Web Tokens☆6,476May 1, 2025Updated 11 months ago
- Reverse proxies cheatsheet☆1,857Nov 4, 2023Updated 2 years ago
- Monitor linux processes without root permissions☆5,952Mar 1, 2026Updated last month
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆8,837Dec 4, 2025Updated 4 months ago
- The cheat sheet about Java Deserialization vulnerabilities☆3,170May 26, 2023Updated 2 years ago
- This tool generates gopher link for exploiting SSRF and gaining RCE in various servers☆3,341Apr 18, 2023Updated 2 years ago
- Serverless GPU API endpoints on Runpod - Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.☆636Dec 3, 2024Updated last year
- GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.☆12,892Apr 7, 2026Updated last week
- A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me☆2,336Nov 29, 2024Updated last year
- Pwn stuff.☆1,809May 31, 2022Updated 3 years ago
- A list of useful payloads and bypass for Web Application Security and Pentest/CTF☆76,854Updated this week
- HTTPLeaks - All possible ways, a website can leak HTTP requests☆2,102Jan 3, 2026Updated 3 months ago
- PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)☆19,649Updated this week
- ☆351Jan 24, 2023Updated 3 years ago
- RSA attack tool (mainly for ctf) - retrieve private key from weak public key and/or uncipher data☆6,884Mar 21, 2026Updated 3 weeks ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.☆6,153Aug 14, 2024Updated last year
- Self contained htaccess shells and attacks☆1,077Feb 17, 2022Updated 4 years ago
- ☆705Nov 27, 2024Updated last year
- Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.☆239Oct 8, 2024Updated last year
- Collection of steganography tools - helps with CTF challenges☆2,657Nov 27, 2022Updated 3 years ago
- Collection of CTF Web challenges I made☆2,829Aug 31, 2025Updated 7 months ago
- Collections of Orange Tsai's public presentation slides.☆750Jan 1, 2025Updated last year
- Fast web fuzzer written in Go☆15,866Apr 24, 2025Updated 11 months ago
- Content-Type Research☆661Jun 29, 2025Updated 9 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- JNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n. This tool can be used to start an HTTP S…☆936Sep 2, 2025Updated 7 months ago
- Fancy reverse and bind shell handler☆2,883Aug 9, 2024Updated last year
- HTTP.ninja☆148Sep 3, 2023Updated 2 years ago
- List of XSS Vectors/Payloads☆1,369Jan 14, 2026Updated 3 months ago
- Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and n…☆11,141Apr 7, 2026Updated last week
- Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3☆2,067Jan 2, 2024Updated 2 years ago
- Build a database of libc offsets to simplify exploitation☆1,859Oct 23, 2024Updated last year