Skip to content
View Kassapu's full-sized avatar

Block or report Kassapu

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

PHP 8,737 2,122 Updated Nov 10, 2023

🎯 Command Injection Payload List

3,648 746 Updated Jul 18, 2024

Automatic SSRF fuzzer and exploitation tool

Python 3,411 554 Updated Sep 4, 2025

Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.

Python 73 23 Updated Mar 12, 2022

Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3

Python 2,038 328 Updated Jan 2, 2024

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Python 6,977 1,123 Updated Aug 28, 2025

My Python Examples

Python 34,370 12,831 Updated Nov 25, 2025

List of awesome reverse engineering resources

9,767 1,136 Updated Jul 29, 2023

This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security,…

Jupyter Notebook 24,189 4,603 Updated Nov 26, 2025

Crawlee—A web scraping and browser automation library for Python to build reliable crawlers. Extract data for AI, LLMs, RAG, or GPTs. Download HTML, PDF, JPG, PNG, and other files from websites. Wo…

Python 7,220 522 Updated Nov 24, 2025

🔬Collection of malware, ransomware, RATs, botnets, stealers, etc.

C++ 221 166 Updated Dec 15, 2021

Clone of svn repository of http://insecurety.net/projects/web-malware/ project

PHP 465 240 Updated Oct 18, 2016

A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

JavaScript 2,239 218 Updated Nov 29, 2024

A list of interesting payloads, tips and tricks for bug bounty hunters.

6,309 1,603 Updated Sep 14, 2023

A collection of PHP exploit scripts, found when investigating hacked servers. These are stored for educational purposes and to test fuzzers and vulnerability scanners. Feel free to contribute.

PHP 852 232 Updated Feb 26, 2024

Pwn stuff.

PHP 1,805 392 Updated May 31, 2022

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Python 3,245 398 Updated Apr 18, 2023

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

Python 3,789 405 Updated Oct 4, 2025

🎯 XML External Entity (XXE) Injection Payload List

1,275 329 Updated Jul 18, 2024

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

Python 12,654 3,088 Updated Oct 21, 2024

fsociety Hacking Tools Pack – A Penetration Testing Framework

Python 11,691 2,096 Updated Aug 8, 2024

🥧 HTTPie CLI — modern, user-friendly command-line HTTP client for the API era. JSON support, colors, sessions, downloads, plugins & more.

Python 37,099 3,783 Updated Dec 17, 2024

An opinionated list of awesome Python frameworks, libraries, software and resources.

Python 271,265 26,792 Updated Nov 20, 2025

XSS payloads designed to turn alert(1) into P1

JavaScript 1,379 226 Updated Sep 12, 2023

Webshell && Backdoor Collection

PHP 1,959 1,040 Updated Apr 6, 2020

Automatically exported from code.google.com/p/domxsswiki

HTML 546 80 Updated May 12, 2018

X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter

Perl 1,696 481 Updated Oct 8, 2023

Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.

699 131 Updated Nov 19, 2025

💻⚠️ A curated collection of awesome malware, botnets, and other post-exploitation tools.

263 33 Updated Mar 14, 2021

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

Python 2,408 469 Updated May 6, 2024
Next