Skip to content
View hpy's full-sized avatar

Highlights

  • Pro

Block or report hpy

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
39 stars written in Python
Clear filter

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 76,422 16,793 Updated Mar 16, 2026

Scrapy, a fast high-level web crawling & scraping framework for Python.

Python 60,972 11,401 Updated Mar 27, 2026

Never use print for debugging again

Python 16,607 956 Updated Mar 8, 2026

Create randomly insecure VMs

Python 2,749 327 Updated Mar 25, 2026

cve-search - a tool to perform local searches for known vulnerabilities

Python 2,607 618 Updated Mar 28, 2026

SSRF (Server Side Request Forgery) testing resources

Python 2,481 493 Updated Oct 12, 2024

Reverse proxies cheatsheet

Python 1,855 222 Updated Nov 4, 2023

declutters url lists for crawling/pentesting

Python 1,540 169 Updated Feb 23, 2025

REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications

Python 1,323 150 Updated Aug 7, 2025

A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.

Python 1,286 239 Updated Aug 18, 2025

Convolutional neural network for analyzing pentest screenshots

Python 1,280 147 Updated Mar 8, 2026

Active Directory Integrated DNS dumping by any authenticated user

Python 1,149 126 Updated Apr 4, 2025

Create tar/zip archives that can exploit directory traversal vulnerabilities

Python 1,041 190 Updated Jun 3, 2021

A library for detecting known secrets across many web frameworks

Python 788 77 Updated Mar 29, 2026

The 'exploitable' GDB plugin

Python 747 122 Updated Aug 13, 2022

Viewgen is a ViewState tool capable of generating both signed and encrypted payloads with leaked validation keys

Python 659 89 Updated Feb 1, 2025

Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.

Python 562 85 Updated Mar 8, 2025

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

Python 409 43 Updated Dec 24, 2022

RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.

Python 367 87 Updated Apr 14, 2022

This repository includes a set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate. The objective is to simplify as much as possible t…

Python 294 43 Updated Mar 25, 2026

Grammar-based HTTP/1 fuzzer with mutation ability

Python 262 32 Updated Oct 30, 2024

Turbo Intruder Scripts

Python 229 59 Updated Jun 11, 2020

HeapHopper is a bounded model checking framework for Heap-implementations

Python 228 17 Updated Jul 2, 2025

OSINT scanning tool which discovers and maps directories found in javascript files hosted on a website.

Python 227 32 Updated Feb 24, 2019

SALT - SLUB ALlocator Tracer for the Linux kernel

Python 158 22 Updated Sep 10, 2018

List HackerOne private program assets

Python 155 24 Updated Jun 24, 2021

jsonp is a Burp Extension which attempts to reveal JSONP functionality behind JSON endpoints.

Python 154 29 Updated Feb 15, 2021

Detects request smuggling via HTTP/2 downgrades.

Python 94 9 Updated Jul 30, 2022

Home Assistant SunPower Integration using the local installer ethernet interface.

Python 94 37 Updated Sep 30, 2025

A framework built on top of Burp's Python Scripter extension.

Python 91 22 Updated Dec 28, 2023
Next