This is your work, valued

Morocco

Jakom

Elite
@j4k0m

Sr. Penetration Tester / Web Addict

godkiller. Vulnerabilities you my miss during a penetration testing.

97

discord-theory-I. My attempt to reverse the Discord nitro token generation function.

29

MultiTapBurp. A Burp Suite extension that helps track and manage multiple sessions simultaneously by color-coding HTTP requests based on custom patterns.

28

CVE-2021-24499. Mass exploitation of CVE-2021-24499 unauthenticated upload leading to remote code execution in Workreap theme.

16

glimpse-into-web-penetration-testing. A glimpse into web penetration testing example, that I did me and @Edd13Mora in our free time, for beginners to have an idea about websec.

14

secdojo-23jan. SecDojo 23jan CTF writeup.

14

CVE-2021-41773. Exploitation of CVE-2021-41773 a Directory Traversal in Apache 2.4.49.

13

really-good-cybersec. A really good cybersec reading materials.

13

lookuper. A simple tool for wide targeting using ASN.

10

DiscordEmojisStealer. Use emojis everywhere without having a nitro or steal other emojis to use them on your server.

9

BundleScout. A tool designed to extract and analyze React Native bundles from Android APK files. It provides insights into the structure and content of the JavaScript code within the APK, identifying API endpoints, potential secrets, and other relevant information.

8

ultimateclone. script to clone all your 42 projects at once

8

PHPTickler. A fast, reliable and lightweight PHP code scanner for detecting XSS, SQLi, Path Traversal, and RCE vulnerabilities.

8

WinUSBKiller. C#

7

CVE-2018-18925. Exploitation of CVE-2018-18925 a Remote Code Execution against the Git self hosted tool: Gogs.

7

Ruby2.x-RCE-Deserialization. Code execution by using a Ruby Universal Gadget when an attacker controls the data passed to Marshal.load().

6

SimplePyInteractsh. Python-based integration for Interactsh client, designed for registering and managing interactions.

6

spring4shell-secdojo. A write-up for SecDojo Spring4shell lab.

5

CVE-2019-5420. A vulnerability can allow an attacker to guess the automatically generated development mode secret token.

5

CVE-2018-0114. Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.

4

Boxer. Auto scanning tool that will help you during playing on HackTheBox, TryHackMe...etc

4

API-to-Shell. Exploiting API to Shell challenge from Pentesterlab serialize badge.

4

Hack-the-Box-OSCP-Preparation. Hack-the-Box-OSCP-Preparation

4

CVE-2016-2098. Remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data.

4

PHP-8.1.0-dev-RCE. Script to exploit PHP-8.1.0-dev-RCE and gain reverse shell.

4

RyouYoo.

4

AllAboutBugBounty. All about bug websites (bypasses, payloads, and etc)

3

auto_42_projecter. A tool that will create 42 project files structure for you.

3

PenTestMethodology2020. PenTest Methodology 2020

3

loader-CVE-2020-14343. A web application vulnerable to CVE-2020-14343 insecure deserialization leading to command execution in PyYAML package.

3

thnb-ctf-writeups. Writeups for the challenges I made for THNB national CTF

3

3DPrint-Lite-1.9.1.4-File-Upload. Analysis of WordPress 3D Print Lite 1.9.1.4 - arbitrary file upload vulnerability.

3

Vault6. Archiving Leaked samples from Different sources for Different Uses

2

RT. A Raytracing program from scratch in C language, with complex shapes, texture mapping, soft shadows, multiple lights and fractals.

2

CVE-2018-11235. Auto malicious git repository creation to exploit CVE-2018-11235 a Remote Code Execution using Git Sub module.

2

Struts-s2-045. Exploit script of Remote Code Execution in Struts 2 application.

2

unhide-the-flag. unhide the flag ! stego challenge by Lelouche01

2

CBC-MAC. Exploitation of signature of non-fixed size messages with CBC-MAC challenge on Pentesterlab.

2

php-reverse-shell. PHP

2

filterbypass. Browser's XSS Filter Bypass Cheat Sheet

2

SecurityTesting. Shell

2

recheck. recheck script for 42 projects

2

ReconNotes. Just some public notes that can be useful and i want let the world knows.

2

Parth. Heuristic Vulnerable Parameter Scanner

2

Awesome-WAF. 🔥 Everything awesome about web-application firewalls (WAF).

2

PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF

2

Reconizer. Shell

2

RazXSS. Easy XSS web challenge.

2

axiom. The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!

1

Burp2Discord. A Burp Suite extension that allows you to send HTTP requests and responses directly to Discord via webhooks.

1

solidity-hacking. Hacking smart contracts training

1

dirty_snap. A script to generate malicious snap package.

1

CVE-2016-10033. Remote Code Execution vulnerability in PHPMailer.

1

hacking_env. Shell

1

liffy. Local file inclusion exploitation tool

1

gatsby-portfolio-dev. A portfolio for developers

1

CTFS_SETUP. those are some ctfs that I made while learning !

1