Skip to content
View edwinsiebel's full-sized avatar
Block or Report

Block or report edwinsiebel

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

A tool to perform Sequential Import Chaining

Rust 247 16 Updated Sep 11, 2019

Python wrapper for ysoserial-all.jar that makes exploiting Java deserialization much easier

Python 2 Updated Aug 29, 2023

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 5,665 1,293 Updated Mar 10, 2021

🔍A dependency-aware GraphQL API fuzzing tool

Python 57 4 Updated Jul 27, 2024

Reverse shell listener and payload generator designed to work on most Linux targets

C 70 16 Updated Jul 22, 2024

Contextual Deserialization vulnerability that causes RCE - Remote Code Execution

Java 14 6 Updated Apr 28, 2024

fastjson auto type derivation search

Java 22 3 Updated Aug 19, 2021

Automated Python Code Injection Tool

Python 86 25 Updated Oct 13, 2021

CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.

Java 64 1 Updated Jul 2, 2024

GitOps for your Tailscale ACLs

79 22 Updated Jun 18, 2024

Unsecure time-based secret exploitation and Sandwich attack implementation Resources

Python 100 9 Updated Jun 30, 2024

CORS Misconfiguration Scanner

Python 1,307 168 Updated Sep 17, 2022
Python 55 14 Updated Jul 3, 2024

A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.

1,789 299 Updated Sep 5, 2021

A python Flask app that generates dynamic DTDs for easy out-of-band data exfiltration.

Python 5 1 Updated Jun 8, 2024

Self contained htaccess shells and attacks

Shell 1,005 192 Updated Feb 17, 2022

A blind XXE injection callback handler. Uses HTTP and FTP to extract information. Originally written in Ruby by ONsec-Lab.

Python 510 88 Updated Jul 29, 2020

Dependency Confusion Security Testing Tool

Python 39 2 Updated Jul 21, 2022

Exploits for CNEXT (CVE-2024-2961), a buffer overflow in the glibc's iconv()

Python 329 42 Updated Jul 26, 2024

GQLSpection - parses GraphQL introspection schema and generates possible queries

Python 56 6 Updated Jun 21, 2024

Scalpel is a Burp extension for intercepting and rewriting HTTP traffic, either on the fly or in the Repeater using Python 3 scripts.

Python 46 1 Updated May 31, 2024

Hides message with invisible Unicode characters

Go 64 4 Updated Jun 24, 2024

grep rough audit - source code auditing tool

Shell 1,456 238 Updated Apr 9, 2024

Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets!

Go 309 18 Updated Jul 28, 2024

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

Python 355 37 Updated Dec 24, 2022

graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.

Python 523 62 Updated Jul 3, 2024

Security Auditor Utility for GraphQL APIs

Python 331 50 Updated Jun 20, 2024

GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)

Python 1,339 188 Updated Mar 11, 2024

Proxmox VE Helper-Scripts

Shell 12,129 1,875 Updated Jul 28, 2024
Next