# fill in what you have — every command below updates live, unset ones stay as {TOKENS}
# set your target domain — dorks and recon commands below update live
grep -i
# further reading — the sources behind this list
-rw-r--r--PayloadsAllTheThings# the full, exhaustive version of everything here
-rw-r--r--HackTricks# deep-dive methodology for every category here
-rw-r--r--AwesomeXSS# curated XSS payloads, polyglots and context-breaking tricks
-rw-r--r--PortSwigger XSS Cheat Sheet# payloads filterable by injection context
-rw-r--r--SSRF-Testing# cujanovic's SSRF payload and bypass collection
-rw-r--r--ssti-advanced-payload-list# 2000+ SSTI payloads across template engines
-rwxr-xr-xCORScanner# automated CORS misconfiguration scanner
-rw-r--r--google-dorks-bug-bounty# TakSec's dork list — the source for the Google Dorks category
guest@mmr:~/cheatsheets$ ./codec.sh --interactive
Pick an operation below — it runs immediately against the input. Paste the output back into the input to chain steps by hand. Everything runs locally in your browser, nothing is sent anywhere.
--key
$ codec--help