Skip to content
View luisfontes19's full-sized avatar
πŸ€“
πŸ€“

Organizations

@TheSecurityVault @DamnVulnerableCryptoApp

Block or report luisfontes19

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
luisfontes19/README.md

Hey there! πŸ‘‹

Security Engineer by profession, Hacker by passion

I've been breaking things professionally for almost a decade as a Product/Application Security Engineer, but I've been tinkering with security for 20 years (yes, I started young 😎).

πŸš€ Some of My Projects

πŸ—Ό WatchTower - VSCode extension that scans your workspace for malicious configurations, invisible Unicode threats, and dangerous IDE attack vectors β€” fully local, fully open source.

πŸ”‘ How To Test Secrets - A visual, interactive cheat-sheet for testing whether leaked API keys and secrets are still valid β€” pick a service and get a ready-to-run command.

🎭 MirageVM - Javascript virtual machine for code obfuscation. It can be used to protect sensitive client side logic with custom bytecode. Supports all Javascript features through a custom low level language (Private project)

πŸ›‘οΈ Orgsec Guide - A comprehensive checklist and guide for organizations looking to implement a robust cybersecurity program

πŸ’₯ XXExploiter - Tool to help exploit XXE vulnerabilities. Generates XML payloads and automatically starts a server to serve DTD's or do data exfiltration

πŸ”ͺ VSCode Swissknife - Scriptable VSCode extension to generate or manipulate data. Stop pasting sensitive data in webpages

πŸ”“ DamnVulnerableCryptoApp - An app with intentionally insecure crypto implementations. Perfect for testing/exploiting weak cryptography and learning crypto without diving deep into the math

#️⃣ hash-identifier-js - Port from hash-identifier to javascript


πŸ› οΈ Languages

Daily drivers:

JavaScript/TypeScript β€’ Node.js β€’ Express β€’ React
Python β€’ Django β€’ Flask

The old friends (a bit rusty, but we go way back):

Java β€’ Spring β€’ Ruby/Rails β€’ C# β€’ PHP

πŸ’¬ Beyond Code

🎀 Occasional speaker at security conferences

πŸ“š Currently trying to write a fictional book (stay tuned!)

✍️ Sharing knowledge on TheSecurityVault

Pinned Loading

  1. xxexploiter xxexploiter Public

    Tool to help exploit XXE vulnerabilities

    TypeScript 592 68

  2. DamnVulnerableCryptoApp/DamnVulnerableCryptoApp DamnVulnerableCryptoApp/DamnVulnerableCryptoApp Public

    An app with really insecure crypto. To be used to see/test/exploit weak cryptographic implementations as well as to learn a little bit more about crypto, without the need to dive deep into the math…

    TypeScript 86 23

  3. CSRFER CSRFER Public

    Tool to generate csrf payloads based on vulnerable requests

    TypeScript 64 14

  4. DamnVulnerableCryptoApp/BeOnTime DamnVulnerableCryptoApp/BeOnTime Public

    Simple tool to test for TIming Attacks

    TypeScript

  5. thecombiner thecombiner Public

    Combines supplied words and generates all possible combinatios/permutations. Can also hash wordlist entries to look for an hash match

    TypeScript 2

  6. vscode-swissknife vscode-swissknife Public

    Scriptable VSCode extension to generate or manipulate data. Stop pasting sensitive data in webpages.

    TypeScript 53 8