This is your work, valued

Piotr Duszynski

Elite
@drk1wi

Modlishka. Modlishka. Reverse Proxy.

5.4k

Portspoof. Portspoof

2.4k

HeaderScan. "HeaderScan" Burp Plugin

16

Shr3dKit. Red Team Tool Kit

16

Red_Team. Some scripts useful for red team activities

13

bypass_waf. waf自动爆破(绕过)工具

10

WebViewApps. Swift

9

evilginx2. Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication

7

xploits.

6

muraena. Muraena is an almost-transparent reverse proxy aimed at automating phishing and post-phishing activities.

5

password_cracking_rules. One rule to crack all passwords. or atleast we hope so.

5

AndroidProjectCreator. Convert an APK to an Android Studio Project using multiple open-source decompilers

5

SirepRAT. Remote Command Execution as SYSTEM on Windows IoT Core

5

beautiful-jekyll. :sparkles: Build a beautiful and simple website in literally minutes. Demo at http://deanattali.com/beautiful-jekyll

4

xss-payload-list. 🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List

4

cve-2019-1003000-jenkins-rce-poc. Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline: Declarative)

4

sploits. C++

4

rescope. Parse scope definitions to Burp Suite / ZAP compatible formats for import

4

Exploits. Windows Exploits

4

domained. Multi Tool Subdomain Enumeration

4

juicy-potato. A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM.

4

stuffz. Basically a script thrift shop

4

muddyc3. Leaked Muddyc3 C2 source.

3

frida-scripts. A collection of my Frida.re instrumentation scripts to facilitate reverse engineering of mobile Apps.

3

blog.github.io. Build a Jekyll blog in minutes, without touching the command line.

3

exploit-database. The official Exploit Database repository

3

fuzzdb. Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

3

pocs. C

3

sqlmap. Automatic SQL injection and database takeover tool

3

Face-Depixelizer. Face Depixelizer based on "PULSE: Self-Supervised Photo Upsampling via Latent Space Exploration of Generative Models" repository.

3

exploit_generator. Automated Exploit generation with WinDBG

3

assets.

3

dlinject. Inject a shared library (i.e. arbitrary code) into a live linux process, without ptrace

2

webshellz. Various Web Shells

2

JNI-Frida-Hook. Script to quickly hook natives call to JNI in Android

2

portspoof.github.io. HTML

2

fpmvuln. bash poc scripts to exploit open fpm ports

2

DetectFrida. Detect Frida for Android

2

Noah. Lightweight node/service registry inspired by Apache Zookeeper

2

ewus. eWUS - PHP library implementing eWUS functionality

2

WP-Vulnerabilities-Exploits. Huge Collection of Wordpress Exploits and CVES

2

Vectors. reboot spear phishing

2

delete-self-poc. A way to delete a locked, or current running executable, on disk.

2

cloudformation-templates. AWS CloudFormation templates for common tasks.

2

rev-regexp-lib. Reverse regular expression C++ library

2

CVE-2021-26855. Go

2

strong-frida. make frida strong, bypass frida detection.

1

Lagrange. A minimalist Jekyll theme for running a personal blog

1

Blind-XSS-SVG. Blind XSS SVG

1

SkCodecFuzzer. Fuzzing harness for testing proprietary image codecs supported by Skia on Android

1

duszynski.github.io.

1

kpn-security-policy. KPN Security Policy

1

osx. Unofficial GitHub-import of OS X source packages from http://opensource.apple.com/

1

struts-scan. Python2编写的struts2漏洞全版本检测和利用工具

1