Starlog — Page 25
// LATEST
Developer Tools
CORStest: Hunting Misconfigured Cross-Origin Policies at Scale
Developer Tools
Auditing S3 Bucket Exposures: A Security Researcher's Download Tool
Automation
DVCS-Pillage: The Security Tool That Exposes Your Forgotten .git Directories
Cybersecurity
CloudGoat: Learning Cloud Penetration Testing by Breaking Things on Purpose
Developer Tools
Pathbrute: Exploit-Aware Directory Enumeration for Penetration Testing
Developer Tools
Mining Robots.txt for Security Intelligence: Inside RobotsDisallowed
Developer Tools
Hunting Java Deserialization Exploits with Graph Traversal: Inside Inspector-Gadget
Cybersecurity
WhatWeb: Ruby-Powered Web Fingerprinting with 1800+ Plugins for Security Reconnaissance
Developer Tools
sshuttle: The Transparent Proxy That Turns SSH Into a VPN Without the VPN Overhead
Data & Knowledge
Commonspeak2: Mining Google BigQuery to Generate Wordlists from Real Internet Traffic
Developer Tools
Anatomy of S2-057: Understanding Struts2's Namespace Vulnerability Through Live Exploitation
AI Dev Tools
Photon: The Multi-Threaded OSINT Crawler That Weaponizes Web Archives
Automation
Tracy: Browser-Based Taint Tracking That Bypasses the Proxy Tax
Cybersecurity
RecurseBuster: Why HEAD-First Requests Make Recursive Content Discovery Faster
Developer Tools
git-secrets: Why Client-Side Git Hooks Still Matter for Credential Protection
AI Dev Tools
unfurl: The Bug Bounty Hunter's Secret Weapon for URL Parsing
Cybersecurity
Mining Bug Bounty Scopes at Scale: Inside bounty-targets-data's Automated Intelligence Pipeline
AI Dev Tools
CeleryStalk: Building a Distributed Security Scanner on Top of Python's Task Queue
Developer Tools
Archaeologit: Why Deleting Secrets From Your Repo Isn't Enough
Cybersecurity
Sn1per: The Shell-Script Orchestrator That Weaponized 90+ Security Tools
Cybersecurity
Learning Go for Security Work: A Deep Dive into parsiya/Hacking-with-Go
Cybersecurity
SpiderFoot: How 200+ OSINT Modules Communicate in a Publisher/Subscriber Pipeline
AI Dev Tools
HASSH: Fingerprinting SSH Implementations Before the Encryption Kicks In
Automation