Barcelona, Spain

Luis Toro (@lobuhisec)

Expert
@lobuhi

Security Consultant. I do things with kubernetes.

byp4xx. 40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

1.9k

kindscaler. Node Management for KinD Clusters

81

awrbacs. AWACS for RBAC. Tool for auditing CRUD permissions in Kubernetes' RBAC.

46

lobuhi.github.io. Rebujito is a fork of IppSec.Rocks and serves as a repo for hacking tools and other resources such as vulnerable apps, cheatsheets or methodologies.

9

adet. Bash script for DNS file exfiltration using Invoke-DNSteal in server side.

7

nanny. Cares the child processes. Bash script to watch and save the whole command of any child process given a PID

7

kuball. Multicontext CLI for kubectl. All contexts at once or by keyword.

6

BurpSuite_403Bypasser. Burpsuite Extension to bypass 403 restricted directory

4

entrophylter. Take the crunch output and filter results for its entropy.

4

privilege-escalation-awesome-scripts-suite. PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)

4

nginxpwner. Python

3

nucleitemplates. My custom nuclei templates

3

nuclei-burp-integration. Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.

2

kubeaudit. kubeaudit helps you audit your Kubernetes clusters against common security controls

2

adventofcode. Just my personal challenge to complete some Advent of Code challenges just using bash script and (eventually) one-liners. #ChatGPT

2

HateHunter. HateHunter: Detect Hate Speech on YouTube with AI

2

Hack-Comands. Compilation of commands for hacking tasks and security tools as a bit of everything

2

openvpn-install. Set up your own OpenVPN server on Debian, Ubuntu, Fedora, CentOS or Arch Linux.

2

kubetools. Kubetools - Curated List of Kubernetes Tools

1

policies. Kyverno policies for security and best practices

1

operator. Kubernetes operator for installing Calico and Calico Enterprise

1

auger. Directly access data objects stored in etcd by kubernetes.

1

SecLists. SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

1

harpoon. A collection of scripts, and tips and tricks for hacking k8s clusters and containers.

1

ntlm_bruter. Bruteforce NTLM HTTP authentication. This fork uses a single list in user:passwd format.

1

entropy. shannon entropy

1

rtl8821CU. Realtek RTL8811CU/RTL8821CU USB Wi-Fi adapter driver for Linux

1

dnsteal. DNS Exfiltration tool for stealthily sending files over DNS requests.

1

elastalert. Easy & Flexible Alerting With ElasticSearch

1

Mitigating-Web-Shells. Guidance for mitigation web shells. #nsacyber

1

pytm. A Pythonic framework for threat modeling

1
31
Apply