Skip to content
View devploit's full-sized avatar
🦊
Bug whisperer. Sometimes I create them, sometimes I hunt them. Balance is key
🦊
Bug whisperer. Sometimes I create them, sometimes I hunt them. Balance is key

Organizations

@eyeem @freepik-company @ripp3rs

Block or report devploit

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
devploit/README.md

Hey there! 🦊

View counter

Hi, I'm Daniel Púa (a.k.a. devploit), offensive security researcher from Cádiz, Spain. I lead security at Magnific and spend the rest of my time breaking things for a living: bug bounty, penetration testing and code review across web, mobile and APIs. Everything I publish ends up at devploit.dev.

🧰 Things I build and keep online

  • JWTForge: decode, audit and break JWTs entirely in your browser. Six attack generators, zero requests sent.
  • pwny.cc: a curated payload repository for security researchers.
  • x-utils: twelve copy-paste console tools that pull metrics from X without paying for the API. Read-only, no server, no password.
  • nomore403: bypass 403/40X responses. 1.9k+ stars, and the reason many of you are here.

🔎 Research

Assigned CVEs across WordPress plugins and the Node.js ecosystem (adm-zip, decompress, pathe), with public advisories and write-ups on the blog. The up-to-date list, with CVSS scores and references, is at devploit.dev/cves.

🏁 Competitive security

CTF player since 2017 with SFPE, ex ripp3rs. The full record of placements and podiums, solo and team, is at devploit.dev/ctf. Represented Spain in the European Cybersecurity Challenge (ECSC) and mentored the national team the year after. I also organise Hack&Beers Málaga.

Same mindset in all of it: If it parses, it breaks. 🧨

👤 Social / Content:

Website: devploit.dev GitHub: devploit Blog: devploit Twitter: devploit Linkedin: Daniel Púa

🐛 Bug Bounty:

HackerOne: devploit Bugcrowd: devploit Intigriti: devploit YesWeHack: devploit

🛡️ CTF & Security:

CTFTime: devploit HackTheBox: devploit

Pinned Loading

  1. nomore403 nomore403 Public

    🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.

    Go 1.9k 220

  2. awesome-ctf-resources awesome-ctf-resources Public

    A list of Capture The Flag (CTF) frameworks, libraries, resources and software for started/experienced CTF players 🚩

    793 110

  3. debugHunter debugHunter Public

    Discover hidden debugging parameters and uncover web application secrets

    JavaScript 248 7

  4. x-utils x-utils Public

    Free copy-paste browser console tools for X: who does not follow you back, which posts actually work, bookmarks export, fake follower detection. No API keys, no password, nothing leaves your browser.

    HTML