Skip to content
View empty-jack's full-sized avatar

Block or report empty-jack

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

Python 1,037 282 Updated Jan 7, 2026

Mobile Edge-Dynamic Unified Security Analysis

JavaScript 2,156 295 Updated Jan 13, 2026

Fake Protocol Server

Python 1,606 184 Updated Jan 2, 2025

Monitor linux processes without root permissions

Go 5,836 565 Updated Jan 17, 2023

Various wordlists for bruteforce

Python 35 7 Updated Nov 9, 2021

A vulnerable application exposing Spring Boot Actuators

Java 123 31 Updated Feb 25, 2019
Go 185 25 Updated Jun 17, 2025

Trac is an enhanced wiki and issue tracking system for software development projects (mirror)

Python 528 171 Updated Dec 8, 2025

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

Python 2,310 597 Updated Dec 22, 2025

Nginx configuration static analyzer

Python 8,548 444 Updated Jul 28, 2024

A list of interesting payloads, tips and tricks for bug bounty hunters.

6,344 1,609 Updated Sep 14, 2023

Come and join us, we need you!

Python 9,157 1,428 Updated Jan 9, 2026

A modern vulnerable web app

HTML 1,014 371 Updated Mar 11, 2021

Prototype Pollution and useful Script Gadgets

1,571 216 Updated Jan 27, 2024

CTFs as you need them

Python 6,474 2,554 Updated Jan 14, 2026

The Burp extension to check JWT (JSON Web Tokens) for using keys from known from public sources

Java 136 14 Updated Sep 21, 2020

Framework for blind boolean-based sql injections exploatation. Use it if sqlmap does shit.

Jupyter Notebook 29 2 Updated Mar 26, 2022

DIVA Android - Damn Insecure and vulnerable App for Android

Java 1,068 318 Updated May 19, 2023

Sonar is a security researcher's Swiss army knife for finding and exploiting vulnerabilities that require out-of-band interactions

Go 19 5 Updated Jan 14, 2026

Another way to bypass WAF Cheat Sheet (draft)

431 65 Updated Nov 28, 2018

Exploit for CVE-2019-11043

Go 1,834 250 Updated Nov 12, 2019

GraphQL application security testing helper

Python 20 5 Updated May 22, 2023

A collection of android security related resources

Shell 9,107 1,532 Updated Jan 13, 2026

Find web directories without bruteforce

Python 1,950 272 Updated Oct 29, 2023

Python utility to takeover domains vulnerable to AWS NS Takeover

Python 87 28 Updated Feb 2, 2023

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 74,367 16,503 Updated Jan 3, 2026

Pentest/BugBounty progress control with scanning modules

Python 282 47 Updated Jul 16, 2020
Python 3 Updated Oct 20, 2016

A runtime mobile application analysis toolkit with a Web GUI, powered by Frida, written in Python.

JavaScript 1,456 232 Updated Jun 3, 2021

A demo of cross-origin login detection for most major web platforms

HTML 859 84 Updated Feb 25, 2022
Next