This is your work, valued
SUID3NUM. A standalone python script which utilizes python's built-in modules to enumerate SUID binaries, separate default binaries from custom binaries, cross-match those with bins in GTFO Bin's repository & auto-exploit those, all with colors! ( ͡~ ͜ʖ ͡°)
676SiteBroker. A cross-platform python based utility for information gathering and penetration testing automation!
430sliver-cheatsheet. Sliver CheatSheet for OSEP
297subdomainsEnumerator. A docker image which will enumerate, sort, unique and resolve the results of various subdomains enumeration tools.
71ine-dl. Download INE courses including labs, exercises, quizzes, slides, and, videos!
48An0n-3xPloiTeR-Shell. An0n 3xPloiTeR Shell
35anime-dl. Python3 script to download subbed animes from 4anime.to, gogoanime.ai, and gogoanime.be (the sites with best quality i.e. 1080p)
28decoder. A simple script to try and decode a string in various encoding mechanisms regardless of its (original) type.
26ReVeRsE-IP. A Python Based Non-Interactive Ugly ReVeRsE IP Script To Find The Domains On The Server
20BOF. Some Buffer Overflow Automation Scripts I'll be using between PWK labs and Exam!
19IpGrabber. It'll grab the IP sitting behind Cloudflare ¯\_(ツ)_/¯
19csgo-server. Creating CS:GO server with skins, ws, gloves, knife, rank, rs, etc. both with a bash file and using a docker file.
16Php-Obfuscation-Tool. A php based obfuscation tool for obfuscating scripts using various methods ¯\_(ツ)_/¯
15S3miNa. A python based utility to download animes for offline viewing ¯\(ツ)/¯
13S3VideoStreamer. Playing videos through S3 buckets (Wasabi, AWS, etc.) through client-side VideoJS player
12infosecinstitute-dl. A small and dirty python3 based script to download courses from Infosec Institute.
12Mini-Shell. A Simple PHP Based Mini Web-Shell for command execution, directory browsing etc.
121337-Language-Translator. 1337 Language Translator Can Be Used to Convert Text into Leet Language
9Route53-SubdomainsTakeover. A script to fetch all route53 hosted zones, fetch all CNAME DNS records of each zone (domain) then check all the records containing elasticbeanstalk applications; if they're takeoverable and post all that on Slack!
8cyberhackathon.pk. This repository contains the challenges solutions of cyberhackathon.pk
8webApplicationTakeover. Vanilla PHP based application containing the challenge of taking over Web Application via Shell Upload (docker image & documentation will be available at: https://pentestlabs.gitbook.io/challenges/)
6vulnerable-packages. A repository containing docker images of vulnerable packages (e.g. backdoored vsftpd) etc. for testing exploits/scanners and to not waste time on dependencies and shit.
6VUBot. A script to post Quizzes, GDBs, and Assignments in Discord channel via WebHooks to alert the assignee.
5Anon-Exploiter.
5adminPanelTakeover. Laravel based application containing the challenge of taking over Admin Panel (docker image & documentation will be available at: https://pentestlabs.gitbook.io/challenges/admin-panel-takeover-i)
5sast-dast. Implement SAST+DAST checks using github actions against a vulnerable python application which allows RCE. Goal is to detect it before it gets pushed into production.
5Parameter-Finder. It Can Be Very Useful In Case Of Finding Parameters Of Php Files In A Site
5R3V-Injector. It can be used for injecting / appending backdoors recursively
4AES-Killer. Burp plugin to decrypt AES Encrypted traffic of mobile apps on the fly
4exploits. Repository containing any exploits I'll be writting while preparing for OSWE or while doing general CTFs/challenges.
4Symlinker. It Can Be Used In Bypassing Internel Server Error and grabbing config files of website's hosted ¯\_(ツ)_/¯
4API-Security-Checklist. Checklist of the most important security countermeasures when designing, testing, and releasing your API
4CRTO-Lab-Status. Posts the latest status of CRTO labs, running/stopped and hours in Discord/Slack
3linux-smart-enumeration. Linux enumeration tool for pentesting and CTFs with verbosity levels
3String-Conversion-Tool. It Can Be Used For Doing Various String Conversions ¯\_(ツ)_/¯
3code-snippets. A Github repo maintaining (mostly) python code snippets which I use approximately daily and to save time searching for them locally/via google
3sparta. Network Infrastructure Penetration Testing Tool
3hetty. Hetty is an HTTP toolkit for security research. It aims to become an open source alternative to commercial software like Burp Suite Pro, with powerful features tailored to the needs of the infosec and bug bounty community.
3Sherlock. PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.
3Default-Credentials. Default usernames and passwords for various systems (VoIP,IPMI,Oracle).
3xvwa. XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
3BurpBounty. Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.
3udemy-dl. A cross-platform python based utility to download courses from udemy for personal offline use.
3frida-interception-and-unpinning. Frida scripts to directly MitM all HTTPS traffic from a target mobile application
2scripthunter. Tool to find JavaScript files on Websites
2anon-exploiter.github.io. Github pages site hosting content of umar0x01.sh
2Scouter. This repository maintains some of the scripts made by Ebryx DevSecOps team.
2pentestlabs. Here you'll find the docker images of challenges/vulnerabilities/misconfigurations/flaws faced by `(mostly) me and the bois` while pentesting different kinds of applications.
2AWAE-PREP. This repository will serve as the "master" repo containing all trainings and tutorials done in preperation for OSWE in conjunction with the AWAE course. This repo will likely contain custom code by me and various courses.
2Php-Calculator. Just An Php Calculator ^_^
2devops-essentials-sample-app. HTML
1PyHEIC2JPG. Effortlessly convert HEIC images to JPG format
1CSGO-MVP. Custom MVP Anthem For CSGO.
1anandtiwarics.
1Useful-Commands. [CS:GO] Useful Commands
1github-actions. Python
1RMS-Runtime-Mobile-Security. Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime
1