Skip to content
View kingthorin's full-sized avatar
🇨🇦
Open Source !!
🇨🇦
Open Source !!

Organizations

@zaproxy

Block or report kingthorin

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…

Go 5,133 941 Updated Jan 16, 2026

A curated collection of awesome things related to status badges

Markdown 855 62 Updated Jan 11, 2026

The CLI for working with JSON Schema. Covers formatting, linting, testing, bundling, and more for both local development and CI/CD pipelines

Shell 227 24 Updated Jan 19, 2026

A web browser with dynamic data-flow tracking enabled in the Javascript engine and DOM, based on Mozilla Firefox (https://github.com/mozilla-firefox/firefox). It can be used to identify insecure da…

JavaScript 154 21 Updated Jan 19, 2026
TypeScript 642 124 Updated Apr 9, 2025

Hide secret messages in plain sight using invisible Unicode variation selectors!

HTML 3 Updated Aug 27, 2025

The official repository of Mozilla's Firefox web browser.

JavaScript 11,033 824 Updated Jan 20, 2026

BBT - Bug Bounty Tools (examples💡)

Python 1,871 474 Updated Apr 5, 2024

A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB.

1,233 202 Updated Jan 11, 2026

Damn Vulnerable Restaurant is an intentionally vulnerable Web API game for learning and training purposes dedicated to developers, ethical hackers and security engineers.

Python 881 162 Updated Jan 3, 2026

BChecks collection for Burp Suite Professional and Burp Suite DAST

761 134 Updated Jan 12, 2026

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting) vulnerabilities on sites where injections are blocke…

HTML 540 85 Updated Jan 16, 2026

A high performance go implementation of Wappalyzer Technology Detection Library

Go 956 153 Updated Jan 19, 2026

HTTP Archive fork of Wappalyzer

JavaScript 98 45 Updated Jan 19, 2026

ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.

PHP 2,226 378 Updated Jan 8, 2026

Unicode characters that will translate a single character to multiple characters in domain names or TLD's

50 1 Updated Nov 23, 2024

Using django to simulate SQL injection and HTTP Parameter Pollution

1 Updated Mar 18, 2022

A python script that finds endpoints in JavaScript files

Python 4,245 651 Updated Apr 13, 2024

Awesome Vulnerable Applications

1,334 202 Updated Jan 19, 2026

Chapar is a simple and easy to use api testing tools aims to help developers to test their api endpoints. it support http and grpc protocols.

Go 683 38 Updated Jan 8, 2026

A fast tool to scan CRLF vulnerability written in Go

Go 1,506 148 Updated Jan 10, 2026

The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving to…

Python 657 88 Updated Sep 19, 2025

Sasori is a dynamic web crawler powered by Puppeteer, designed for lightning-fast endpoint discovery.

JavaScript 147 17 Updated Jul 23, 2024

BugBountyTips

JavaScript 414 85 Updated Jul 31, 2025

CORS Misconfiguration Scanner

Python 1,493 186 Updated Sep 17, 2022

A collection of HAR files for developing against the HAR spec

JavaScript 6 2 Updated Mar 4, 2025

Complex payload encoder

Go 238 26 Updated Jan 20, 2024

Automagically reverse-engineer REST APIs via capturing traffic

HTML 9,205 343 Updated Jan 19, 2026
Java 2 1 Updated Jan 7, 2026
Next