Skip to content
View gosirys's full-sized avatar

Highlights

  • Pro

Block or report gosirys

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

HackingTools

666 repositories

Check your WAF before an attacker does

Python 1,469 184 Updated Jul 17, 2025

一款基于BurpSuite的被动式shiro检测插件

Java 1,797 160 Updated Dec 14, 2022

Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules thro…

Java 1,781 343 Updated Apr 26, 2024

gup aka Get All Urls parameters to create wordlists for brute forcing parameters.

Go 18 7 Updated Dec 4, 2021

WordPress Plugin Update Confusion

Python 67 18 Updated Dec 7, 2021

🍪 CookieMonster helps you detect and abuse vulnerable implementations of stateless sessions.

Go 967 74 Updated Jan 10, 2025

🚀 Caido releases, wiki and roadmap

Shell 2,195 115 Updated Mar 4, 2026

Detects request smuggling via HTTP/2 downgrades.

Python 94 9 Updated Jul 30, 2022

A Nmap XSL implementation with Bootstrap.

HTML 967 186 Updated Nov 13, 2023

Scan only once by IP address and reduce scan times with Nmap for large amounts of data.

Rust 394 42 Updated Aug 2, 2025

SSRF Proxy facilitates tunneling HTTP communications through servers vulnerable to Server-Side Request Forgery.

Ruby 480 73 Updated Jan 1, 2018

A tool to exploit .NET Remoting Services

C# 534 110 Updated Jul 31, 2024

Client Side Prototype Pollution Scanner

JavaScript 523 63 Updated Sep 17, 2022

A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.

Go 518 74 Updated Jun 22, 2022

Take a list of domains/subdomains and probe for working http/https server.

Go 192 33 Updated Sep 8, 2020

Bypassing WAF by abusing SSL/TLS Ciphers

Python 322 73 Updated Jul 27, 2021

Grammar-based HTTP/1 fuzzer with mutation ability

Python 261 32 Updated Oct 30, 2024

A sqlmap tamper script for manipulating parameters within a serialized PHP array.

Python 5 2 Updated Jun 15, 2017

有关burpsuite的插件(非商店),文章以及使用技巧的收集(此项目不再提供burpsuite破解文件,如需要请在博客mrxn.net下载)---Collection of burpsuite plugins (non-stores), articles and tips for using Burpsuite, no crack version file

HTML 3,842 709 Updated Dec 26, 2025

Albatar is a SQLi exploitation framework in Python

Python 137 36 Updated Jan 24, 2025

automated web assets enumeration & scanning [DEPRECATED]

Python 288 60 Updated Mar 7, 2023

A Burp Suite extension to extract datas from source code while browsing.

Python 160 39 Updated Mar 20, 2024

Struts2漏洞扫描利用工具 - Golang版. Struts2 Scanner Written in Golang

Go 571 92 Updated Jan 10, 2022

Next generation web scanner

Ruby 6,453 980 Updated Oct 19, 2025

Cloudflare, Sucuri, Incapsula real IP tracker.

Python 1,768 235 Updated Jul 25, 2023

HTTP parameter discovery suite.

Python 6,115 852 Updated Feb 20, 2025

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

Python 1,851 236 Updated May 20, 2024

Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.

Python 560 85 Updated Mar 8, 2025

知识星球《漏洞百出》最新 20条 Topic

114 10 Updated Nov 30, 2021

weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-32…

Python 2,070 336 Updated Nov 24, 2023