tsug0d / PentestQALinks
Pentest Q&A trick written in Vietnamese
☆10Updated 6 years ago
Alternatives and similar repositories for PentestQA
Users that are interested in PentestQA are comparing it to the libraries listed below
Sorting:
- Things help you get started with Java Vulnerability☆73Updated 2 years ago
- Collection of my capture-the-flag web challenge in any levels☆112Updated 2 years ago
- Challenges I wrote for various CTF competitions☆44Updated last year
- A collection of Server-Side Prototype Pollution gadgets and exploits☆205Updated 7 months ago
- This repository stores some of my custom BCheck Scan configurations. Its goal is to identify intriguing elements that warrant further man…☆102Updated last year
- This repository contains various XXE labs set up for different languages and their different parsers. This may alternatively serve as a p…☆111Updated last year
- This is the data that powers the PortSwigger URL validation bypass cheat sheet.☆52Updated 4 months ago
- Collection of quirky behaviours of code and the CTF challenges that I made around them.☆28Updated 4 years ago
- ☆28Updated last year
- Client-Side Prototype Pollution Tools☆85Updated 3 years ago
- Searcher for cross-site leaks (XS-Leaks)☆82Updated 2 years ago
- Awesome MXSS ??☆53Updated 11 months ago
- ☆76Updated last week
- PP-finder Help you find gadget for prototype pollution exploitation☆178Updated last year
- CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.☆148Updated last year
- Here i will post my writeups :)☆33Updated 2 years ago
- My CTF writeups☆17Updated 5 years ago
- A chrome/Firefox extension to retrieve and load react javascript chunks all at once for a wide range of javascript techs☆71Updated 3 months ago
- ☆32Updated last year
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆55Updated 4 months ago
- A simple tool to detect vulnerabilities described here https://portswigger.net/research/browser-powered-desync-attacks.☆36Updated 3 years ago
- Blog about HTTP Request Smuggling, including a demo application.☆29Updated 3 years ago
- A Burp Suite extension for CSRF proof of concepts.☆52Updated 2 years ago
- Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes☆31Updated 2 years ago
- A demo PHP application used to exercise SQL injection techniques in a safe, local Docker environment☆44Updated last year
- An intentionally-vulnerable application for demonstrating the hazards of SpEL expression composition☆28Updated 7 years ago
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations☆78Updated this week
- ✨ Build a beautiful and simple website in literally minutes. Demo at https://beautifuljekyll.com☆21Updated 2 years ago
- CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).☆137Updated 5 months ago
- ☆65Updated last year