A tool that transforms Firefox browsers into a penetration testing suite
Role in this project:
Security Engineer Contributions:14 commits, 6 PRs, 15 pushes in 4 years 5 months
Contributions summary:Mazin's commits primarily focused on creating a tool that transforms a Firefox browser into a penetration testing suite. They wrote a Bash script that automates the download and installation of various security-related Firefox add-ons such as HackBar, Wappalyzer, and Foxy Proxy. The script also includes features to download Burp Suite certificates, enhancing the browser's security capabilities. The user consistently updated the script, releasing versions with added add-ons and features reflecting the tool's evolution.
firefox-browserpenetration-testing
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
Role in this project:
Back-end Developer & Security Engineer Contributions:2 releases, 6 reviews, 62 commits in 10 months
Contributions summary:Mazin primarily contributed to the security and functionality of the log4j-scan tool. Their commits added new features such as the integration of DNS callback providers, including Interact.sh, for vulnerability detection. They refactored proxy setup, and added a disable redirects option, and implemented testing and payloads for CVE-2021-45046 and CVE-2022-42889, enhancing the tool's effectiveness in identifying and exploiting Log4j vulnerabilities. Furthermore, they made code adjustments to improve the tool's usability, such as rstrip lines when reading file input and fixing a bug with the wait time.
cvelog4jrce