Skip to content
View kingthorin's full-sized avatar
🎯
#OpenSource
🎯
#OpenSource

Organizations

@zaproxy

Block or report kingthorin

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB.

1,062 163 Updated Jan 29, 2025

Damn Vulnerable Restaurant is an intentionally vulnerable Web API game for learning and training purposes dedicated to developers, ethical hackers and security engineers.

Python 493 89 Updated Feb 23, 2025

BChecks collection for Burp Suite Professional and Burp Suite Enterprise Edition

669 120 Updated Feb 25, 2025
JavaScript 211 30 Updated Feb 14, 2025

A high performance go implementation of Wappalyzer Technology Detection Library

Go 813 130 Updated Mar 9, 2025

HTTP Archive fork of Wappalyzer

JavaScript 57 27 Updated Mar 3, 2025

ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.

PHP 1,978 349 Updated Mar 7, 2025

Unicode characters that will translate a single character to multiple characters in domain names or TLD's

40 1 Updated Nov 23, 2024

Using django to simulate SQL injection and HTTP Parameter Pollution

1 Updated Mar 18, 2022

A python script that finds endpoints in JavaScript files

Python 3,851 613 Updated Apr 13, 2024

Awesome Vulnerable Applications

1,124 171 Updated Aug 7, 2024

Chapar is a simple and easy to use api testing tools aims to help developers to test their api endpoints. it support http and grpc protocols.

Go 542 32 Updated Mar 5, 2025

A fast tool to scan CRLF vulnerability written in Go

Go 1,399 145 Updated Mar 4, 2025

The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving to…

Python 602 84 Updated Nov 21, 2024

Sasori is a dynamic web crawler powered by Puppeteer, designed for lightning-fast endpoint discovery.

JavaScript 133 14 Updated Jul 23, 2024

BugBountyTips

JavaScript 404 82 Updated Jun 5, 2024

CORS Misconfiguration Scanner

Python 1,394 181 Updated Sep 17, 2022

A collection of HAR files for developing against the HAR spec

JavaScript 6 2 Updated Mar 4, 2025

Complex payload encoder

Go 219 25 Updated Jan 20, 2024

Automagically reverse-engineer REST APIs via capturing traffic

HTML 8,739 312 Updated Mar 3, 2025
Java 2 1 Updated Feb 21, 2025
Python 98 38 Updated Mar 7, 2025

Attack surface detector that identifies endpoints by static analysis

Crystal 671 48 Updated Mar 9, 2025

An innovative superfamily of fonts for code

TypeScript 15,472 267 Updated Mar 7, 2025

Library for accessing HTTP Archives (HAR) with Java

Java 92 29 Updated Mar 1, 2025

🌐 Identify the technologies powering any website. This is a fork of the now deleted Wappalyzer project by @AliasIO and community.

JavaScript 264 46 Updated Jun 22, 2024

Security interview questions with possible explanation for roles in AppSec, Pentesting, Cloud Security, DevSecOps, Network Security and so on

326 63 Updated Dec 28, 2024

Intel One Mono font repository

9,524 314 Updated Oct 16, 2024

Simple websites vulnerable to Server Side Template Injections(SSTI)

PHP 388 87 Updated Mar 16, 2023

Detectify Crowdsource Challenge

Shell 67 16 Updated Apr 26, 2022
Next