Skip to content
View tk-t0n0y's full-sized avatar
:atom:
403 🐱‍👤
:atom:
403 🐱‍👤
  • localhost

Block or report tk-t0n0y

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

32 results for forked starred repositories
Clear filter

Uility to embed XXE and XSS payloads in docx,odt,pptx,etc (OXML_XEE on steroids)

Python 2 1 Updated Jul 22, 2020

A tool for append URLs, skipping duplicates & combine parameters.

Go 1 2 Updated Sep 12, 2020

DNSTake — A fast tool to check missing hosted DNS zones that can lead to subdomain takeover

Go 1 Updated Apr 15, 2022

Login hunter of default credentials for administrative web interfaces leveraging NNdefaccts dataset.

Lua 315 56 Updated Nov 21, 2020

Automated blind-xss search for Burp Suite

Python 24 6 Updated Mar 28, 2022

API Security Project aims to present unique attack & defense methods in API Security field

1 Updated Mar 6, 2022

Fast and reliable python script that makes active and/or passive scan to obtain subdomains and search for open ports.

Python 1 Updated Mar 8, 2022

SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files

Python 1 Updated Oct 1, 2021

Quick SQLMap Tamper Suggester

Python 1 Updated Oct 5, 2020

Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration

Go 1 Updated Feb 5, 2022

Searching for virtual hosts among non-resolvable domains

Python 1 Updated Apr 29, 2020

Hidden parameters discovery suite

Python 1 Updated Jul 29, 2021

Change monitoring app that checks the content of web pages in different periods.

JavaScript 1 Updated Sep 29, 2021

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more...

Go 1 Updated Sep 27, 2021

Exfiltrate blind remote code execution output over DNS via Burp Collaborator.

Python 1 Updated Dec 7, 2020

An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.

Shell 3 5 Updated Jul 13, 2021

Burp Plugin to decrypt AES encrypted traffic on the fly

Java 14 4 Updated May 13, 2021

This repo is meant to be a list of companies that hire security people full remote.

1 Updated Aug 11, 2021

Fetch many paths for many hosts - without killing the hosts

Go 3 3 Updated Jan 4, 2022

monitors certificate transparency logs

Python 1 Updated May 29, 2021

A burp suite extension that reviews backup, old, temporary and unreferenced files on web server for sensitive information (OWASP OTG-CONFIG-004)

Java 1 Updated Sep 18, 2018

Fetches javascript file from a list of URLS or subdomains.

Go 1 Updated Jan 6, 2021

Small utility program to perform multiple operations for a given subnet/CIDR ranges.

Go 1 Updated Jul 13, 2021

burpsuite extension for check unauthorized vulnerability

Python 1 Updated Oct 7, 2020

A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration

Python 1 Updated Sep 11, 2020

Collections of tools and methods created to aid in OSINT collection

Python 2 Updated Jul 4, 2021

Gotator is a tool to generate DNS wordlists through permutations.

Go 1 Updated Jun 15, 2021

Rewrite of the popular wireless network auditor, "wifite" - original by @derv82

Python 923 162 Updated Sep 11, 2024

The project contains multiple shell scripts for automating the tasks during recon.

Shell 2 Updated Jul 19, 2022
Next