Skip to content
View hpy's full-sized avatar

Highlights

  • Pro

Block or report hpy

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Quickly find differences and similarities in disassembled code

Java 2,510 162 Updated Apr 3, 2025

The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.

TypeScript 358 38 Updated Oct 3, 2023

A set of simple servers (currently HTTP/HTTPS and DNS) which allow configurable and scriptable responses to network requests.

Python 62 6 Updated Aug 5, 2022

A Burp Suite extension for finding DNS vulnerabilities in web applications!

Java 94 14 Updated Sep 12, 2023

CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.

Dockerfile 280 38 Updated Aug 24, 2024

IIS shortname scanner written in Go

Go 329 43 Updated Mar 25, 2023

Resources for the deps.dev API

Go 302 24 Updated Apr 15, 2025

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Go 864 109 Updated Jan 12, 2024

This repository includes a set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate. The objective is to simplify as much as possible t…

Python 285 44 Updated Jan 15, 2025

🎤⌨️ Acoustic keyboard eavesdropping

C++ 8,747 601 Updated Jan 15, 2023

Extract JavaScript files from burp suite project with ease.

Kotlin 88 13 Updated Feb 19, 2022

A library for detecting known secrets across many web frameworks

Python 616 55 Updated Apr 14, 2025

The result of scraping over 500 million web pages to form the mother of all wordlists

8 2 Updated Jun 1, 2023

Deploy a SOCKS5 proxy in DigitalOcean and autoconfigure the Burp proxy settings to route all traffic through the droplet

Java 56 10 Updated Oct 23, 2024
Rust 32 7 Updated Feb 10, 2023

REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications

Python 1,044 113 Updated Apr 14, 2025

Grammar-based HTTP/1 fuzzer with mutation ability

Python 250 32 Updated Oct 30, 2024
Go 7 1 Updated Feb 25, 2023

Hidden parameters discovery suite

Rust 1,813 163 Updated Sep 8, 2024

Detects request smuggling via HTTP/2 downgrades.

Python 92 10 Updated Jul 30, 2022

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

Python 385 43 Updated Dec 24, 2022

declutters url lists for crawling/pentesting

Python 1,337 157 Updated Feb 23, 2025

Cybersecurity of Machine Learning and Artificial Intelligence

JavaScript 71 19 Updated Mar 4, 2022

RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.

Python 353 84 Updated Apr 14, 2022

Parse HPROF files from the Spring Boot Heapdump Actuator

Python 26 5 Updated Jun 11, 2024

A tool to dump Java serialization streams in a more human readable form.

Java 1,016 125 Updated Jun 21, 2024

TLS Redirection

120 22 Updated Nov 21, 2017
Go 71 13 Updated Feb 11, 2024

Pre-Built Vulnerable Environments Based on Docker-Compose

Dockerfile 18,697 4,581 Updated Mar 31, 2025
Next
Showing results