This is your work, valued

Umar

Elite
@Anon-Exploiter

SUID3NUM. A standalone python script which utilizes python's built-in modules to enumerate SUID binaries, separate default binaries from custom binaries, cross-match those with bins in GTFO Bin's repository & auto-exploit those, all with colors! ( ͡~ ͜ʖ ͡°)

676

SiteBroker. A cross-platform python based utility for information gathering and penetration testing automation!

430

sliver-cheatsheet. Sliver CheatSheet for OSEP

297

subdomainsEnumerator. A docker image which will enumerate, sort, unique and resolve the results of various subdomains enumeration tools.

71

ine-dl. Download INE courses including labs, exercises, quizzes, slides, and, videos!

48

An0n-3xPloiTeR-Shell. An0n 3xPloiTeR Shell

35

anime-dl. Python3 script to download subbed animes from 4anime.to, gogoanime.ai, and gogoanime.be (the sites with best quality i.e. 1080p)

28

decoder. A simple script to try and decode a string in various encoding mechanisms regardless of its (original) type.

26

ReVeRsE-IP. A Python Based Non-Interactive Ugly ReVeRsE IP Script To Find The Domains On The Server

20

BOF. Some Buffer Overflow Automation Scripts I'll be using between PWK labs and Exam!

19

IpGrabber. It'll grab the IP sitting behind Cloudflare ¯\_(ツ)_/¯

19

csgo-server. Creating CS:GO server with skins, ws, gloves, knife, rank, rs, etc. both with a bash file and using a docker file.

16

Php-Obfuscation-Tool. A php based obfuscation tool for obfuscating scripts using various methods ¯\_(ツ)_/¯

15

S3miNa. A python based utility to download animes for offline viewing ¯\(ツ)/¯

13

S3VideoStreamer. Playing videos through S3 buckets (Wasabi, AWS, etc.) through client-side VideoJS player

12

infosecinstitute-dl. A small and dirty python3 based script to download courses from Infosec Institute.

12

Mini-Shell. A Simple PHP Based Mini Web-Shell for command execution, directory browsing etc.

12

1337-Language-Translator. 1337 Language Translator Can Be Used to Convert Text into Leet Language

9

Route53-SubdomainsTakeover. A script to fetch all route53 hosted zones, fetch all CNAME DNS records of each zone (domain) then check all the records containing elasticbeanstalk applications; if they're takeoverable and post all that on Slack!

8

cyberhackathon.pk. This repository contains the challenges solutions of cyberhackathon.pk

8

webApplicationTakeover. Vanilla PHP based application containing the challenge of taking over Web Application via Shell Upload (docker image & documentation will be available at: https://pentestlabs.gitbook.io/challenges/)

6

vulnerable-packages. A repository containing docker images of vulnerable packages (e.g. backdoored vsftpd) etc. for testing exploits/scanners and to not waste time on dependencies and shit.

6

VUBot. A script to post Quizzes, GDBs, and Assignments in Discord channel via WebHooks to alert the assignee.

5

Anon-Exploiter.

5

adminPanelTakeover. Laravel based application containing the challenge of taking over Admin Panel (docker image & documentation will be available at: https://pentestlabs.gitbook.io/challenges/admin-panel-takeover-i)

5

sast-dast. Implement SAST+DAST checks using github actions against a vulnerable python application which allows RCE. Goal is to detect it before it gets pushed into production.

5

Parameter-Finder. It Can Be Very Useful In Case Of Finding Parameters Of Php Files In A Site

5

R3V-Injector. It can be used for injecting / appending backdoors recursively

4

AES-Killer. Burp plugin to decrypt AES Encrypted traffic of mobile apps on the fly

4

exploits. Repository containing any exploits I'll be writting while preparing for OSWE or while doing general CTFs/challenges.

4

Symlinker. It Can Be Used In Bypassing Internel Server Error and grabbing config files of website's hosted ¯\_(ツ)_/¯

4

API-Security-Checklist. Checklist of the most important security countermeasures when designing, testing, and releasing your API

4

CRTO-Lab-Status. Posts the latest status of CRTO labs, running/stopped and hours in Discord/Slack

3

linux-smart-enumeration. Linux enumeration tool for pentesting and CTFs with verbosity levels

3

String-Conversion-Tool. It Can Be Used For Doing Various String Conversions ¯\_(ツ)_/¯

3

code-snippets. A Github repo maintaining (mostly) python code snippets which I use approximately daily and to save time searching for them locally/via google

3

sparta. Network Infrastructure Penetration Testing Tool

3

hetty. Hetty is an HTTP toolkit for security research. It aims to become an open source alternative to commercial software like Burp Suite Pro, with powerful features tailored to the needs of the infosec and bug bounty community.

3

Sherlock. PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.

3

Default-Credentials. Default usernames and passwords for various systems (VoIP,IPMI,Oracle).

3

xvwa. XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.

3

BurpBounty. Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.

3

udemy-dl. A cross-platform python based utility to download courses from udemy for personal offline use.

3

frida-interception-and-unpinning. Frida scripts to directly MitM all HTTPS traffic from a target mobile application

2

scripthunter. Tool to find JavaScript files on Websites

2

anon-exploiter.github.io. Github pages site hosting content of umar0x01.sh

2

Scouter. This repository maintains some of the scripts made by Ebryx DevSecOps team.

2

pentestlabs. Here you'll find the docker images of challenges/vulnerabilities/misconfigurations/flaws faced by `(mostly) me and the bois` while pentesting different kinds of applications.

2

AWAE-PREP. This repository will serve as the "master" repo containing all trainings and tutorials done in preperation for OSWE in conjunction with the AWAE course. This repo will likely contain custom code by me and various courses.

2

Php-Calculator. Just An Php Calculator ^_^

2

devops-essentials-sample-app. HTML

1

PyHEIC2JPG. Effortlessly convert HEIC images to JPG format

1

CSGO-MVP. Custom MVP Anthem For CSGO.

1

anandtiwarics.

1

Useful-Commands. [CS:GO] Useful Commands

1

github-actions. Python

1

RMS-Runtime-Mobile-Security. Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

1