Skip to content
View inflictx's full-sized avatar

Block or report inflictx

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
inflictx/README.md

header

typing

Standoff365 BI.ZONE based

GET /inflictx HTTP/2
Host: standoff365.com
User-Agent: hunter/2026 (recon-first; app-model) burpsuite/pro
Accept: text/vnd.critical-bugs

HTTP/2 200 OK
X-Handle:    alexander · @inflictx
X-Role:      application security researcher · bug bounty hunter
X-Based:     moscow, ru (gmt+3)
X-Focus:     broken access control · idor / bola · cross-tenant authz
X-Auth:      oauth & sso redirect_uri bypass · session/token leakage · 2fa step-up bypass · ato chains
X-Also:      api data exposure (pii) · ai/llm (prompt injection · system-prompt leak) · ssrf · dom/stored xss
X-Method:    recon-first · model the app before payloads · raw-http proof · strict self-triage
X-Status:    hunting

Stack

Python Bash JavaScript Linux Kali Git Docker


Offline arsenal for pentesters & bug bounty hunters, open-sourced.
payloads · click-to-build commands · GTFOBins · checklists · one search across everything. fully offline, RU/EN.

live demo stars release license

Popular repositories Loading

  1. Arsenal Arsenal Public

    Offline-first, searchable arsenal for pentesting & bug bounty: payloads, a click-to-build command generator, GTFOBins, wordlists, embedded CyberChef, reverse shells, checklists & an engagement trac…

    CSS 162 22

  2. awesome-bug-bounty awesome-bug-bounty Public

    Forked from itsmohitnarayan/awesome-bug-bounty

    A curated list of resources, tools, and wordlists for bug bounty hunters.

    1

  3. Awesome-Hacking Awesome-Hacking Public

    Forked from Hack-with-Github/Awesome-Hacking

    A collection of various awesome lists for hackers, pentesters and security researchers

    1

  4. inflictx inflictx Public

  5. PayloadsAllTheThings PayloadsAllTheThings Public

    Forked from swisskyrepo/PayloadsAllTheThings

    A list of useful payloads and bypass for Web Application Security and Pentest/CTF

    Python

  6. p0wny-shell p0wny-shell Public

    Forked from flozz/p0wny-shell

    Single-file PHP shell

    PHP