Skip to content
View Hacking-Notes's full-sized avatar
📖
ⓘ Hacking Activity Detected
📖
ⓘ Hacking Activity Detected

Block or report Hacking-Notes

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Hacking-Notes/README.md

Hacking Notes

Followers Website Blog Discord


$ whoami
Passionate cyber security enthusiast — building tools, breaking apps,
and documenting the path from script kiddie to security professional.

$ cat ~/.motto
"True power lies in the ability to see what others cannot."
🐛  Bug Bounty Contributions

Search Engine
᲼᲼
Governments / Municipalities
᲼᲼
Domain Providers
᲼᲼
Hotel Chains
᲼᲼
...

📒 Discover more about my related work in my blog articles.


🤝  CVE Contributions

CVE-2024-51490
᲼᲼
CVE-2024-51486
᲼᲼
CVE-2024-51489
᲼᲼
CVE-2024-51380
᲼᲼
CVE-2024-51381
᲼᲼
...

Explore my full collection of CVEs in the CVE repository.


🧭 Main Resources

➜ Hacking Notes (RedTeam & BlueTeam) ⬅ ➜ Roadmap to Hacking Mastery ⬅
Unlock a wealth of hacking wisdom in my notes. Curated by seasoned experts, they offer concise insights into the world of cybersecurity. Perfect for beginners and veterans alike — dive in and elevate your hacking prowess today. Discover the roadmap to hacking mastery. Whether you're a hobbyist, aspiring certifier, or degree seeker, our curated resources and structured paths will guide you. From networking basics to advanced penetration testing, cultivate the hacker mindset.
Hacking Notes Hacker Roadmap
➜ Note Taking - BurpSuite Obsidian Integration ⬅ ➜ ClickMe - Multistep Clickjacking Tool ⬅
Struggling with chaotic notes? Learn my effective note-taking system, including a specialized tool and structured methodology, designed to enhance productivity and collaboration. ClickMe is a powerful multi-step clickjacking tool designed for security professionals. Create, visualize, and demonstrate complex clickjacking attacks with customizable elements and real-time preview.
Burp x Obsidian ClickMe

🧰 The Arsenal

Tool Description
🖱 ClickMe Multi-step clickjacking POC framework
🧬 HR-Smuggler HTTP request smuggling detection (HTTP/1.1 & HTTP/2)
🌐 Subdomain-Takeover Subdomain enumeration & takeover detection
🕸 Wayback-Crawler Async subdomain discovery via Wayback + CT logs
🔎 Endpoint-JS-Explorer Bookmarklet to extract endpoints from JS
💤 lazy-js Extract lazy-loaded filenames from webpack maps
🔑 JWT Chrome extension for JWT security testing
🧩 Extensions Curated Chrome extensions for hackers
🔖 Bookmarks Curated hacker bookmark collection

🎓 Certifications & Guides

Guide Description
🗺 Hacker-Roadmap The complete path from beginner to pro
🟠 BSCP Burp Suite Certified Practitioner exam guidance
🔴 RedTeam Offensive security notes
🔷 BlueTeam Defensive security notes
🧾 CVE Documented CVE research

Pinned Loading

  1. Hacker-Roadmap Hacker-Roadmap Public

    A detailed plan to achieve proficiency in hacking and penetration testing, with pathways including obtaining a degree in cybersecurity or earning relevant certifications.

    Python 1.3k 116

  2. Burp-Suite-Obsidian-Integration Burp-Suite-Obsidian-Integration Public

    Organize, track, and share vulnerability findings effortlessly. This Burp Suite extension integrates with Obsidian, offering a proven note-taking method to streamline bug bounty workflows and enhan…

    Python 51 4

  3. RedTeam RedTeam Public

    This repo offers notes and resources on ethical hacking, covering information gathering, scanning, web hacking, exploitation, and Windows/Linux hacking.

    Python 229 19

  4. ClickMe ClickMe Public

    Clickme is a powerful multi-step clickjacking tool designed for security professionals. Create, visualize, and demonstrate complex clickjacking attacks with customizable elements and real-time prev…

    JavaScript 41 1

  5. jwt jwt Public

    A powerful Chrome extension for security testing and manipulating JWT (JSON Web Tokens) in web applications.

    JavaScript 2

  6. lazy-js lazy-js Public

    A Chrome extension that helps extract and identify lazy-loaded files

    Python 1