Skip to content
View terjanq's full-sized avatar

Organizations

@xsleaks @googlers @justcatthefish @CTF-Organizers

Block or report terjanq

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Searcher for cross-site leaks (XS-Leaks)

JavaScript 81 6 Updated Dec 27, 2022

Automated security reporting from markdown templates (HackerOne and Bugcrowd are currently the platforms supported)

Shell 452 66 Updated May 10, 2019

OWASP CRS (Official Repository)

Python 2,503 405 Updated Mar 29, 2025

Same Origin XSS challenge

HTML 56 5 Updated Apr 7, 2022

XS-Leaks Wiki

HTML 158 41 Updated Feb 1, 2025

A generator of weird files (binary polyglots, near polyglots, polymocks...)

Python 1,209 78 Updated Dec 22, 2024

Client Side Prototype Pollution Scanner

JavaScript 518 63 Updated Sep 17, 2022

Prototype Pollution and useful Script Gadgets

1,468 209 Updated Jan 27, 2024

Writeups for some CTF challenges. I keep the copy of task files in case you would like to try them yourself.

Python 12 Updated Oct 4, 2021

CTF writeups

JavaScript 30 7 Updated May 27, 2022

Content-Type Research

607 63 Updated Feb 8, 2024

The cheat sheet about Java Deserialization vulnerabilities

3,078 598 Updated May 26, 2023

Reverse proxies cheatsheet

Python 1,803 212 Updated Nov 4, 2023

A JavaScript sandbox using proxies

JavaScript 20 3 Updated Jul 18, 2020

justCTF 2019 challenges sources

SystemVerilog 37 6 Updated Jun 9, 2021

Challenge repository for the watevrCTF 2019 CTF competition

C 36 10 Updated Jun 6, 2022

ctf exploit codes or writeups

Python 155 19 Updated Dec 9, 2024

Implementation of attacks on cryptosystems

Python 71 14 Updated May 6, 2021

HTTPLeaks - All possible ways, a website can leak HTTP requests

HTML 2,019 203 Updated Oct 23, 2024

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

JavaScript 14,880 767 Updated Mar 24, 2025

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

PHP 705 108 Updated May 6, 2024

List of XSS Vectors/Payloads

1,221 257 Updated Jan 2, 2025

CTF write-ups

Python 82 25 Updated Dec 1, 2024

A tool to perform Sequential Import Chaining

Rust 262 13 Updated Sep 11, 2019
HTML 2 1 Updated Jul 21, 2020

A collection of browser-based side channel attack vectors.

745 49 Updated Mar 19, 2024

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Python 3,010 386 Updated Apr 18, 2023
Python 3 Updated Jul 23, 2018
Next
Showing results