Skip to content
View w9w's full-sized avatar

Block or report w9w

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

🔭 Reverse engineering JavaScript and CSS sources from sourcemaps

JavaScript 318 44 Updated Jul 25, 2018

Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing

Python 2,915 466 Updated Jun 24, 2024

A fancier postMessage tracker with Chrome Manifest version V3 support and a few additional features, inspired by Frans Rosens postmessage tracker.

JavaScript 102 13 Updated Sep 12, 2025

BackupFinder discovers backup files on web servers by generating intelligent patterns.

Go 98 21 Updated Jul 29, 2025

🐍 A toolkit for testing, tweaking and cracking JSON Web Tokens

Python 6,188 739 Updated May 1, 2025

Automated GitHub secret scanning with smart alerting & monitoring.

Python 27 5 Updated Jul 3, 2025

Fast exfiltration of text using only CSS and Ligatures

Python 83 5 Updated Sep 3, 2025

A Burp extension to Fuzz URLs for HTTP parser inconsistencies

Java 12 2 Updated Jan 9, 2024

Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets!

Go 837 70 Updated Nov 12, 2025

REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications

Python 1,262 143 Updated Aug 7, 2025

A simple script just made for self use for bypassing 403

Shell 1,988 319 Updated May 30, 2024

convert case style of words

Go 54 12 Updated Jan 12, 2024

CeWL is a Custom Word List Generator

Ruby 2,457 304 Updated Oct 21, 2025

update-golang is a script to easily fetch and install new Golang releases with minimum system intrusion

Shell 1,911 228 Updated Jun 27, 2025

Burp Suite extension for testing Passkey systems.

Java 75 4 Updated Apr 1, 2025

A collection of Turbo Intruder scripts.

Python 66 9 Updated Feb 1, 2025

This Chromium extension scans the page for external iFrames, Scripts, and Styles, logs them to the console, and checks if their domains are resolvable.

JavaScript 65 18 Updated Jan 8, 2025

Crack hashes in seconds.

Python 1,847 408 Updated Dec 10, 2024

A tool for adding new lines to files, skipping duplicates

Go 1,594 174 Updated Jan 12, 2024
Shell 8 1 Updated Aug 30, 2021

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

Python 5,487 832 Updated Apr 15, 2025

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting) vulnerabilities on sites where injections are blocke…

HTML 498 75 Updated Nov 4, 2025

AI-powered ffuf wrapper

Python 553 65 Updated Nov 25, 2024

An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability

926 120 Updated Dec 31, 2021

Burp Suite extension that mutates ciphers to bypass TLS-fingerprint based bot detection

Java 424 23 Updated Sep 9, 2025

A fast, clean, responsive Hugo theme.

HTML 12,655 3,261 Updated Oct 26, 2025

A ssh server that knows who you are. $ ssh whoami.filippo.io

Go 2,300 108 Updated Sep 5, 2025

a javascript change monitoring tool for bugbounties

Python 689 110 Updated Jul 31, 2024

This repo contains all the injections mentioned in my talk and enumerators.

JavaScript 130 27 Updated Dec 1, 2023
Next