Skip to content
View kiro6's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report kiro6

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Web pentesting

54 repositories

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,791 1,853 Updated Dec 4, 2025

PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.

PHP 3,759 546 Updated Sep 29, 2025

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Python 31,521 4,406 Updated Mar 6, 2026

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 75,955 16,745 Updated Mar 9, 2026

🎯 Command Injection Payload List

3,690 752 Updated Jul 18, 2024

List of XSS Vectors/Payloads

1,365 270 Updated Jan 14, 2026

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

Python 3,935 413 Updated Oct 4, 2025

Security Auditor Utility for GraphQL APIs

Python 626 86 Updated Nov 20, 2025

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

Python 409 43 Updated Dec 24, 2022

GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations

350 36 Updated Jul 1, 2025

Script to recover mt_rand()'s seed with only two outputs and without any bruteforce.

Python 161 14 Updated Jan 6, 2020

Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.

Python 237 11 Updated Oct 8, 2024

分享PHP WebShell 绕过WAF 的一些经验 Share some experience about PHP WebShell bypass WAF and Anti-AV

PHP 303 74 Updated Oct 30, 2017

Obtain GraphQL API schema even if the introspection is disabled

Python 1,403 123 Updated Dec 5, 2025

Scan for misconfigured S3 buckets across S3-compatible APIs!

Go 3,016 401 Updated Dec 11, 2025

Fast web fuzzer written in Go

Go 15,725 1,522 Updated Apr 24, 2025

JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.

Python 2,916 421 Updated Nov 24, 2021

Fetches JavaScript files quickly and comprehensively.

Go 133 14 Updated May 8, 2023

「🔑」A tool used to hunt down API key leaks in JS files and pages

Go 856 93 Updated Sep 4, 2025

Fast passive subdomain enumeration tool.

Go 13,207 1,514 Updated Mar 11, 2026

httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

Go 9,661 1,043 Updated Mar 9, 2026

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.

Go 4,844 505 Updated Jan 1, 2025

Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing

Python 3,014 471 Updated Mar 7, 2026

PoC of CVE-2024-33883, RCE vulnerability of ejs.

JavaScript 5 Updated Jul 6, 2024

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

PHP 751 114 Updated May 6, 2024

Content-Security-Policy (CSP) Bypass Techniques

76 7 Updated Oct 28, 2020

HTTPLeaks - All possible ways, a website can leak HTTP requests

HTML 2,101 207 Updated Jan 3, 2026

Pure Python hash length extension module

Python 133 24 Updated Jan 28, 2023

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

Python 5,656 902 Updated Jan 5, 2026

🔍 gowitness - a golang, web screenshot utility using Chrome Headless

Go 4,188 425 Updated Jan 21, 2026