Security researcher, bug bounty hunter. Sharing my tools with anyone interested
BypassFuzzer. Fuzz 401/403/404 pages for bypasses
429BypassFuzzer-Burp. The Java Burp Extension version of my BypassFuzzer tool
36burpcollaborator-docker. A set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate in as simple a process as possible
31domainExtractor. Extract domains/subdomains/FQDNs from files and URLs
19vm-setup.sh. My handy bash script to quickly set up debian linux VM's how I like em :)
6DNS-Rebinder. Modified version of cujanovic's dns.py for DNS Rebinding attacks.
4JSCommander. Remotely send JS to execute on clients that connect to your attacker websocket server via XSS.
2linuxprivchecker. linuxprivchecker.py -- a Linux Privilege Escalation Check Script (updated for use with Python 3!)
2subz. Programmatically uses a few subdomain recon tools to enumerate subdomains for a target domain
2ofxpostern. Vulnerability scanner for OFX servers
1bambdas-NetSPI. Bambdas collection for Burp Suite Professional and Community.
1lottochecker. Check Florida lotto numbers
1xsshunter-express. An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!
1