haofree/torrentparse
An exercise in parsing bittorrent files (bdecode) in Python that I did for an interview
Discovered public repositories for haofree in the GitHub catalog.
An exercise in parsing bittorrent files (bdecode) in Python that I did for an interview
Public repository.
Capstone engine: Core + Python + Ocaml + Java + C# bindings
A python subdomain bruteforce tool for pentesters.
Web Content Discovery Tool
WackoPicko is a vulnerable web application used to test web application vulnerability scanners.
A configurable SQL injection test-bed
Extracts plain text from docx files
Uploads a file to Dropbox
Miscellaneous tools and patches that I have written/hacked/forked over the years
Source code to the Crypto Challenges for the CSAW 2010 qualifying CTF
Blazentoo is an Adobe AIR application that can be used to exploit insecure Adobe BlazeDS and LiveCycle Data Services ES servers. Blazentoo provides the ability to seamlessly browse web content, abusing insecurely configured Proxy Services.
SQLBrute is a tool for brute forcing data out of databases using blind SQL injection vulnerabilities.
Demonstration of Manger's Oracle, attacking RSA OAEP
The Deflate Burp Plugin is a plug-in for Burp Proxy (it implements the IBurpExtender interface) that decompresses HTTP response content in the ZLIB (RFC1950) and DEFLATE (RFC1951) compression formats.
This is a Burp Suite plug-in designed to encode and decode WCF Binary Soap request and response data ("Content-Type: application/soap+msbin1). There are two versions of the plug-in available (consult the README for more information).
Tools developed for the book Network Security Tools: Writing, Hacking, and Modifying Security Tools (Published April 2005 by O'Reilly - ISBN 0-596-00794-9). These examples, along with the rest of the examples from the book, are also available from O'Reilly.
Proof of Concept utility for abusing WCF Web Services that use the WSDualHttpBinding in order to perform remote port scans of arbitrary hosts.
Script for easily importing a trusted CA certificate into the iOS Simulator's trust store. This provides application testers the ability to intercept SSL traffic when using the simulator for testing.
Multithreaded SQL union bruteforcer
Automated script for performing Padding Oracle attacks
Public repository.
Python object interface to requests/responses recorded by Burp Suite
Public repository.
AntiXSS for Java is a port of the Microsoft Anti-Cross Site Scripting (AntiXSS) v1.5 library for .NET applications. The library requires Java 1.4 or higher, but has no other prerequisites.
A set of tools made to assist in penetration testing GWT applications. Additional details about these tools can be found on my OWASP Appsec DC slides available here: http://www.owasp.org/images/7/77/Attacking_Google_Web_Toolkit.ppt
IronWASP module to test security of SSL services. Ported from http://www.bolet.org/TestSSLServer/
Public repository.
wifitap updated for BT5r3
Experimental Sublime Text clone
A web shell that allows to run yiic commands and create your own commands.
This a share webshell
The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.
wxNote: Open source copy of Evernote.
RakNet is a cross platform, open source, C++ networking engine for game programmers. A lower level framework powers higher-level features such as game object replication, voice chat, and patching.
Public repository.
Library to load a DLL from memory.
Web Instant Messaging App With Accessible Encryption
博客导出工具
A C++ library with various uses.
Pink's Tracing Library
Website Fingerprinter
Cross-platform utility that uncovers the technologies used on websites.
Public repository.
Quality related stuff for w3af.
Django Web UI contributed by Yandex for w3af.
Source for the w3af web application attack and audit framework, the open source web vulnerability scanner.
Nikto web server scanner
j0llydmper is a windows service that allows you to dump furtively and automaticaly some contents of USB disks just plugged in your computer. In order to dump potentialy interesting files, you can use a rule on the file name or/and on the file size.
If you want to exploit some kernel overflows, I've designed (long time ago) several levels ; have fun!