Popular repositories Loading
-
Java_script_endpoint_extractor
Java_script_endpoint_extractor PublicExtracts hidden API endpoints from JavaScript files and maps them to full URLs for testing. Ideal for bug bounty hunters, red teamers, and anyone doing JS recon at scale.
Shell
-
CORScanner
CORScanner PublicAutomated CORS misconfiguration scanner with PoC exploit generator, bug bounty & pentesting
Python
-
jwt-attack-suite
jwt-attack-suite PublicA comprehensive JWT attack CLI covering every major vulnerability class — from alg:none bypass to RS256→HS256 algorithm confusion, HMAC secret bruteforce, kid header injection (SQLi + path traversa…
Python
-
SQLI-Fingerprinter
SQLI-Fingerprinter PublicDeep SQLi scanner — error/union/boolean/time/OOB, 15 WAF bypasses, 8 DB fingerprints, zero dependencies
Python
-
OAUTH-Flow-Analyzer
OAUTH-Flow-Analyzer PublicOAuth 2.0/OIDC attack suite — state CSRF, redirect_uri bypass (22 variants), PKCE downgrade, scope escalation, token leakage, OIDC flaws
Python
-
SSRF-Callback-Server
SSRF-Callback-Server PublicSelf-hosted Burp Collaborator alternative — DNS+HTTP+HTTPS+SMTP listeners, browser dashboard, cloud metadata detection, 46 SSRF payloads
Python
If the problem persists, check the GitHub status page or contact support.