Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings
@devploit
devploit
Follow
View devploit's full-sized avatar
🦊
Updating pwny.cc...

Daniel Púa (devploit) devploit

🦊
Updating pwny.cc...
Infosec Enthusiast | CTF Player

Block or report devploit

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

WebHacking

41 repositories

A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

JavaScript 2,310 215 Updated Nov 29, 2024

Find domains and subdomains related to a given domain

Go 3,522 534 Updated Jun 7, 2024

🐶 A curated list of Web Security materials and resources.

13,105 1,754 Updated May 2, 2025

Quick SQLMap Tamper Suggester

Python 1,396 277 Updated Jul 18, 2022

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 75,398 16,664 Updated Feb 16, 2026

OSINT tool for discovering the real IP addresses of services which are behind Cloudflare but not properly locked down

Go 154 8 Updated May 1, 2024

Salesforce object access auditor

Python 118 7 Updated Jan 30, 2023

bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.

JavaScript 566 65 Updated Mar 4, 2023

🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.

Python 1,609 244 Updated Oct 31, 2025

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to ...

1,022 156 Updated Jun 24, 2024

重生之我在安全行业讨口子系列,分享在安全行业讨口子过程中,SRC、项目实战的有趣案例

1,132 124 Updated Oct 25, 2024

Blazing fast, advanced Padding Oracle exploit

Go 264 28 Updated Dec 12, 2025

declutters url lists for crawling/pentesting

Python 1,525 168 Updated Feb 23, 2025

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

Ruby 4,520 757 Updated Feb 15, 2026

🍪 CookieMonster helps you detect and abuse vulnerable implementations of stateless sessions.

Go 966 74 Updated Jan 10, 2025

Here I gather all the resources about hacking that I find interesting

Ruby 270 47 Updated Jan 17, 2026

CeWL is a Custom Word List Generator

Ruby 2,575 313 Updated Feb 20, 2026

jsleak is a tool to find secret , paths or links in the source code during the recon.

Go 576 62 Updated Sep 25, 2025

XSS payloads designed to turn alert(1) into P1

JavaScript 1,390 226 Updated Sep 12, 2023

Open Redirection Analyzer

Python 811 112 Updated Mar 5, 2023

Automatic SSRF fuzzer and exploitation tool

Python 3,486 565 Updated Sep 4, 2025

🔓 CLI tool and library to execute padding oracle attacks easily, with support for concurrent network requests and an elegant UI.

TypeScript 216 33 Updated Feb 3, 2023
Python 418 80 Updated Jan 13, 2026

This Burp Suite extension is designed to bypass Web Application Firewalls (WAFs) by padding HTTP requests with dummy data.

Python 6 2 Updated Jul 23, 2023

Bypass Paywalls web browser extension for Chrome and Firefox.

JavaScript 48,098 3,411 Updated Oct 20, 2023
Python 7 Updated Nov 29, 2023

Burp Extension to add additional functionality for pentesting websocket based applications

Java 101 17 Updated Aug 27, 2025

File upload vulnerability scanner and exploitation tool.

Python 3,301 516 Updated May 8, 2025

A fast tool to scan CRLF vulnerability written in Go

Go 1,518 147 Updated Feb 22, 2026

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

6,073 1,197 Updated Aug 14, 2024
Previous 1

AltStyle によって変換されたページ (->オリジナル) /