# Andrax Pentester > Cybersecurity research, education and tooling published by Andrax Pentester, part of the SentinelReign ecosystem. This file indexes what the site publishes first-hand, who writes it, and how to cite it. - Canonical site: https://andraxpentester.in - Generated: 2026-08-29T11:04:57Z - Content last updated: 2026-08-29T09:18:40Z - Companion file: https://andraxpentester.in/llms-full.txt ## Publisher and authorship - [Andrax Pentester](https://andraxpentester.in/about): the publishing organisation. Cybersecurity research, education, and tooling. - [SentinelReign](https://sentinelreign.com): parent organisation. Andrax Pentester is part of this ecosystem; background at https://andraxpentester.in/sentinelreign. - [Founder](https://andraxpentester.in/founder): founder and primary author of Andrax Pentester. - [Syed Zada Abrar](https://andraxpentester.in/authors/syed-zada-abrar): canonical author record and full list of published work. - Verified profiles for Syed Zada Abrar: https://sentinelreign.com, https://github.com/cyb3rvolt3x-A4lixhaS3ntin3l Structured data for these entities is published as JSON-LD on https://andraxpentester.in/ and https://andraxpentester.in/about, using stable node identifiers (`https://andraxpentester.in/#organization`, `https://andraxpentester.in/#website`, `https://andraxpentester.in/founder#person`). ## What this site covers - [Articles](https://andraxpentester.in/articles): Technical analysis and explainers on offensive and defensive security. 31 published. Last updated 2026-08-29T09:18:40Z. - [Tutorials](https://andraxpentester.in/tutorials): Step-by-step, hands-on security instruction with stated prerequisites and tooling. 24 published. Last updated 2026-08-29T06:47:31Z. - [Research](https://andraxpentester.in/research): First-hand vulnerability research: methodology, findings, impact, mitigation, and disclosure timelines. 1 published. Last updated 2026-08-11T11:58:12Z. - [Writeups](https://andraxpentester.in/writeups): Bug bounty, CTF and penetration-test writeups filed under responsible disclosure. 1 published. Last updated 2026-08-11T11:58:12Z. ### Topic areas - [Active Directory](https://andraxpentester.in/categories/active-directory) - [AI Security](https://andraxpentester.in/categories/ai-security): Security of AI agents, LLMs, and the Model Context Protocol (MCP). - [API Security](https://andraxpentester.in/categories/api-security): API security and testing - [Cloud Security](https://andraxpentester.in/categories/cloud-security) - [Cybersecurity](https://andraxpentester.in/categories/cybersecurity): General cybersecurity topics - [Kali Linux](https://andraxpentester.in/categories/kali-linux) - [Offensive Security](https://andraxpentester.in/categories/offensive-security): Offensive security and pentesting - [SQL Injection](https://andraxpentester.in/categories/sql-injection) - [Web Security](https://andraxpentester.in/categories/web-security): Web application security ## Recent articles - [Introducing MCPGrade: Securing Model Context Protocol Servers in 2026](https://andraxpentester.in/articles/introducing-mcpgrade-and-mcp-security-scanner): An exhaustive analysis of 5,308 Model Context Protocol (MCP) servers, introducing the mcpgrade-1.4.0 assessment framework and remediation blueprint. (published 2026-08-29) - [Cloud Security Misconfigurations: The Pentester's Guide to AWS S3, IAM Privilege Escalation & Kubernetes RBAC (2026 Edition)](https://andraxpentester.in/articles/cloud-security-misconfigurations-pentesters-guide-aws-s3-iam-kubernetes-rbac-2026): Master real-world cloud penetration testing. Deep-dive into AWS S3 bucket ACL bypasses, IAM privilege escalation paths, IMDSv2 SSRF vectors, and Kubernetes RBAC cluster takeover with detectio (published 2026-08-29) - [The Ultimate Guide to API Penetration Testing: OWASP Top 10, BOLA, BLA & Exploit Chains](https://andraxpentester.in/articles/the-ultimate-guide-to-api-penetration-testing-owasp-top-10-bola-bla-exploit-chains): An exhaustive 2026 technical guide to API security assessments. Master OWASP API Top 10, BOLA, BFA, mass assignment, GraphQL security, and automated recon tools. (published 2026-08-28) - [Modern Active Directory Attack Paths: Mapping & Exploiting Misconfigurations](https://andraxpentester.in/articles/modern-active-directory-attack-paths-mapping-exploiting-misconfigurations): An in-depth analysis of Active Directory attack paths in 2026, focusing on assumed-breach models, BloodHound mapping, Kerberos misconfigurations, and escalation from low-privilege domain user (published 2026-08-28) - [Penetration Testing Checklist: Complete 2026 Guide](https://andraxpentester.in/articles/penetration-testing-checklist-complete-2026-guide): Master penetration testing with our comprehensive 2026 checklist. From pre-engagement to reporting, this guide covers every phase of a professional pentest with actionable tasks, tools, and b (published 2026-08-23) - [Penetration Testing Types: Black Box, White Box & Gray Box Explained](https://andraxpentester.in/articles/penetration-testing-types-black-box-white-box-gray-box-explained): Discover the three main penetration testing types—Black Box, White Box, and Gray Box—and learn which methodology best fits your security testing needs. Complete guide with real-world scenario (published 2026-08-23) - [Web Application Security Testing: Complete Guide for 2026](https://andraxpentester.in/articles/web-application-security-testing-complete-guide-for-2026): Master web application security testing with this comprehensive guide. Learn testing methodologies, OWASP best practices, essential tools (Burp Suite, ZAP, Nmap), vulnerability assessment tec (published 2026-08-23) - [The Best MCP Servers in 2026 (and How to Vet Them for Security)](https://andraxpentester.in/articles/best-mcp-servers-2026): A curated list of the most useful MCP servers in 2026 — GitHub, Filesystem, Fetch, Slack, Playwright and more — with an honest security note on each and a checklist to vet any server. (published 2026-08-19) - [MCP Prompt Injection and the Lethal Trifecta for AI Agents](https://andraxpentester.in/articles/mcp-prompt-injection-lethal-trifecta): MCP servers can hand an AI agent private data, untrusted content, and a way to exfiltrate it — the lethal trifecta. How prompt injection works over MCP, and how to break the chain. (published 2026-08-19) - [How to Inspect and Test an MCP Server (2026 Guide)](https://andraxpentester.in/articles/how-to-inspect-an-mcp-server): Before you connect an MCP server to your AI agent, inspect it: its tools, input schemas, resources, prompts, and instructions. A step-by-step guide to testing an MCP server safely. (published 2026-08-19) - [MCP Tool Poisoning: How a Malicious Tool Description Hijacks Your AI Agent](https://andraxpentester.in/articles/mcp-tool-poisoning-explained): Tool poisoning hides instructions inside an MCP tool’s description that your AI agent obeys but you never see. Here is how the attack works, its variants, and how to detect it. (published 2026-08-19) - [MCP Security: The Complete Guide to Securing Model Context Protocol Servers (2026)](https://andraxpentester.in/articles/mcp-security-complete-guide): A practitioner’s guide to Model Context Protocol security: the MCP threat model, tool poisoning, prompt injection, rug pulls, and how to vet a server before you connect it to your AI agent. (published 2026-08-19) - [Penetration Testing Salary Guide: How Much Do Pentesters Earn? [2026]](https://andraxpentester.in/articles/penetration-testing-salary-guide-how-much-do-pentesters-earn-2026): Comprehensive penetration testing salary guide for 2026. Discover how much pentesters earn by experience level, location, certification, and industry. Includes salary ranges from junior ($60- (published 2026-08-16) - [Penetration Testing Certification Guide: Best Certs for 2026](https://andraxpentester.in/articles/penetration-testing-certification-guide-best-certs-for-2026): Discover the best penetration testing certifications for 2026. Compare OSCP, CEH, eJPT, PNPT, and more. Learn which cert matches your experience level, career goals, and budget with our compr (published 2026-08-16) - [How to Become a Penetration Tester: Complete Career Roadmap [2026]](https://andraxpentester.in/articles/how-to-become-a-penetration-tester-complete-career-roadmap-2026): Discover the complete roadmap to becoming a penetration tester in 2026. Learn essential skills, certifications, hands-on practice platforms, salary expectations, and proven strategies to brea (published 2026-08-16) ## Recent tutorials - [Hands-On Tutorial: Advanced LLMNR/NBT-NS Poisoning & NTLM Relay Masterclass (2026 Edition)](https://andraxpentester.in/tutorials/hands-on-tutorial-advanced-llmnr-nbt-ns-poisoning-ntlm-relay-masterclass-2026-edition): Complete practical lab guide to LLMNR/NBT-NS poisoning, NetNTLMv2 hash cracking with Hashcat rules, NTLM relaying to SMB/LDAP via ntlmrelayx, and Enterprise SIEM detection. (advanced, 120 min, published 2026-08-29) - [Hands-On Tutorial: Exploiting & Fixing Broken Object Level Authorization (BOLA) in REST APIs](https://andraxpentester.in/tutorials/hands-on-tutorial-exploiting-fixing-broken-object-level-authorization-bola-in-rest-apis): A step-by-step penetration testing lab guide. Learn how to setup a test environment, identify BOLA vulnerabilities using Burp Suite Repeater/Match & Replace, and implement secure code fixes. (advanced, 45 min, published 2026-08-28) - [Step-by-Step Hands-On Guide: Kerberoasting and AS-REP Roasting with Impacket & Hashcat](https://andraxpentester.in/tutorials/step-by-step-hands-on-guide-kerberoasting-and-as-rep-roasting-with-impacket-hashcat): A practical, step-by-step tutorial on identifying, requesting, extracting, and cracking offline password hashes for vulnerable Active Directory Kerberos service accounts. (intermediate, 35 min, published 2026-08-28) - [Linux Text Editors for Pentesters: Vim, Nano & Emacs — Complete Guide 2026](https://andraxpentester.in/tutorials/linux-text-editors-for-pentesters-vim-nano-emacs-complete-guide-2026): Master Nano, Vim, and Emacs text editors for penetration testing on Kali Linux. Learn essential commands, shortcuts, and workflows for editing config files, bash scripts, and analyzing securi (beginner, published 2026-08-23) - [Linux Package Management: apt, dpkg & Snap Complete Guide](https://andraxpentester.in/tutorials/linux-package-management-apt-dpkg-snap-complete-guide): Master the apt package manager, dpkg, and snap in Kali Linux. Learn essential package management commands, repository configuration, and security tool installation for penetration testing in (beginner, published 2026-08-23) - [Linux Process Management & Monitoring Guide: Master Process Control in Kali Linux (2026)](https://andraxpentester.in/tutorials/linux-process-management-monitoring-guide-master-process-control-in-kali-linux-2026): Complete beginner's guide to Linux process management in Kali Linux. Learn process monitoring with ps, top, htop, process control with kill signals, systemd services, resource monitoring, and (beginner, published 2026-08-23) - [Linux Networking Basics: IP, Ports & Protocols - Complete 2026 Guide](https://andraxpentester.in/tutorials/linux-networking-basics-ip-ports-protocols-complete-2026-guide): Master linux networking fundamentals for penetration testing. Learn IP addresses, network interfaces, ports, protocols, DNS configuration, and network troubleshooting tools in Kali Linux. (beginner, published 2026-08-23) - [Bash Scripting for Hackers: Automation Basics (2026 Complete Guide)](https://andraxpentester.in/tutorials/bash-scripting-for-hackers-automation-basics-2026-complete-guide): Master bash scripting fundamentals for penetration testing and ethical hacking. Learn variables, loops, conditionals, functions, and build practical automation scripts for port scanning, subd (beginner, published 2026-08-23) - [Linux User & Group Management for Security: Complete 2026 Guide [Tutorial 15/105]](https://andraxpentester.in/tutorials/linux-user-group-management-for-security-complete-2026-guide-tutorial-15-105): Master Linux administration with this comprehensive guide to user and group management in Kali Linux. Learn useradd, usermod, group permissions, sudo configuration, and security implications (beginner, published 2026-08-16) - [Linux File Permissions & Ownership Explained: Complete Guide for Beginners](https://andraxpentester.in/tutorials/linux-file-permissions-ownership-explained-complete-guide-for-beginners): Master Linux file permissions and ownership in Kali Linux. Learn chmod, chown, SUID, SGID, sticky bits, and how permissions affect penetration testing. Complete guide with practical examples (beginner, published 2026-08-16) - [Linux Terminal Mastery: Command Line for Beginners (2026 Guide)](https://andraxpentester.in/tutorials/linux-terminal-mastery-command-line-for-beginners-2026-guide): Master the Linux terminal from scratch. Learn bash commands, pipes, redirections, environment variables, and essential command line skills for Kali Linux penetration testing. Complete beginne (beginner, published 2026-08-16) - [50+ Essential Linux Commands for Cybersecurity and Ethical Hacking (2026 Guide)](https://andraxpentester.in/tutorials/50-essential-linux-commands-for-cybersecurity-and-ethical-hacking-2026-guide): Master 50+ essential Kali Linux commands for penetration testing and ethical hacking. Complete guide with practical examples, organized by category for beginners to advanced users. (beginner, published 2026-08-16) - [Linux Basics for Hackers: File System & Navigation - Complete Guide 2026](https://andraxpentester.in/tutorials/linux-basics-for-hackers-file-system-navigation-complete-guide-2026): Master the Linux file system hierarchy, navigation commands, and essential directory structures for penetration testing. Learn cd, ls, pwd, find commands and understand critical directories l (beginner, published 2026-08-16) - [Getting Started with Web Reconnaissance](https://andraxpentester.in/tutorials/getting-started-with-web-reconnaissance): Learn the fundamentals of mapping a target web application safely and legally. (beginner, 20 min, published 2026-08-16) - [Kali Linux Single Boot: Complete Bare Metal Installation Guide](https://andraxpentester.in/tutorials/kali-linux-single-boot-complete-bare-metal-installation-guide): Complete guide to installing Kali Linux as a single boot system on bare metal. Learn why single boot offers best performance, step-by-step installation walkthrough, LUKS encryption, partition (intermediate, published 2026-08-15) ## Recent research - [Security Posture of Modern SPA Routing](https://andraxpentester.in/research/security-posture-of-modern-spa-routing): An analysis of common routing patterns in single-page applications and their security implications. (published 2026-08-11) ## Recent writeups - [Stored XSS in Reporting Portal](https://andraxpentester.in/writeups/stored-xss-in-reporting-portal): A responsibly disclosed stored cross-site scripting vulnerability in a public reporting portal. (bug bounty, published 2026-08-11) ## MCP Server Directory - [ilook Face Analysis](https://andraxpentester.in/mcp-servers/ilook-face-analysis) (published 2026-08-29) - [Seah Boon Keong - Chat with BNM API Datasets](https://andraxpentester.in/mcp-servers/seah-boon-keong-chat-with-bnm-api-datasets): MCP for public datasets on BNM Open Data API (Developed by Seah Boon Keong) Allows users to access a wide range of financial and economic data published by Bank Negara Malaysia. Users can retrieve data on various economic indicators such as current exchange rates, OPR, interbank activity, government bond yields, monetary aggregates, reserves, gold prices, consumer alerts, etc. (published 2026-08-28) - [sec-edgar-mcp](https://andraxpentester.in/mcp-servers/sec-edgar-mcp): Access SEC EDGAR financial data through your AI assistant. Search public companies, pull income statements, balance sheets, and cash flows, browse 10-K/10-Q filings, track insider trades, and view historical stock prices. Built for investors, analysts, and finance teams who need fast access to regulatory filings. Uses the free public SEC API. Free tier: 10 calls/day. (published 2026-08-28) - [teppek](https://andraxpentester.in/mcp-servers/teppek): Map-first global classifieds marketplace — post & find jobs, real estate, vehicles & services. (published 2026-08-26) - [OpenArx](https://andraxpentester.in/mcp-servers/openarx-3): Open scientific knowledge MCP for AI agents with three access profiles: search, publish, and govern. (published 2026-08-23) - [pipeworx-gateway](https://andraxpentester.in/mcp-servers/pipeworx-gateway-zsf5tz): City of Peoria, Illinois GIS data including parcels, zoning, permits, and municipal infrastructure via ArcGIS REST API. (published 2026-08-23) - [calculator-mcp-server](https://andraxpentester.in/mcp-servers/cyanheads-calculator-mcp-server): Evaluate, simplify, and differentiate mathematical expressions. (published 2026-08-23) - [france-data](https://andraxpentester.in/mcp-servers/cturkieh-france-data): France Data MCP permet aux agents IA d’interroger, croiser et enrichir automatiquement plusieurs référentiels publics français via une interface MCP unifiée. France Data MCP fournit une couc (published 2026-08-23) - [himalayas/himalayas-mcp](https://andraxpentester.in/mcp-servers/himalayas-himalayas-mcp): Search remote jobs, post job listings, find remote candidates, check salary benchmarks, and manage your career, all through AI conversation. The Himalayas Remote Jobs MCP server connects your AI assistant to the Himalayas remote jobs marketplace in real time. (published 2026-08-23) - [Autario Data Analytics Platform](https://andraxpentester.in/mcp-servers/autario-data): Access 2,300+ verified public datasets from World Bank, IMF, Eurostat, OECD, WHO, FRED, and more. Search, query, and publish data visualizations with real data. ## What you can do - **Search (published 2026-08-23) - [defi-intel](https://andraxpentester.in/mcp-servers/defibabylon-defi-intel): Operator-grade DeFi intelligence MCP. - 10 tools vs DefiLlama's basic 4, - adds governance proposals, - RWA attestation scores, - live X/Twitter narrative. - No enterprise subscription - (published 2026-08-23) - [Ignav Flights](https://andraxpentester.in/mcp-servers/gordgus-ignav-flights): Hosted MCP server providing live flight prices, booking links, and airport lookup for AI agents and travel apps. (published 2026-08-23) - [SteadyFetch](https://andraxpentester.in/mcp-servers/intake-triage-steadyfetch): Reliable web fetching MCP server with built-in retry logic, circuit breaker patterns, caching, and anti-bot bypass. Fetches URLs as raw HTML or clean markdown optimized for LLM consumption. I (published 2026-08-23) - [Coin Railz](https://andraxpentester.in/mcp-servers/travis-kellogg1-coinrailz-mcp): 63 x402 micropayment services via USDC — crypto analytics, trading signals, NASA/ESA satellite data, IoT sensors, AI inference, and prediction markets. Coinbase AgentKit compatible. Pay per c (published 2026-08-23) - [Keyword Research — Google Suggest, Intent & Long-Tail](https://andraxpentester.in/mcp-servers/axel-belfort-keyword-research): SEO keyword research API for AI agents. Generate keyword ideas from Google Suggest with search intent classification (informational/transactional/navigational), long-tail variations, related (published 2026-08-23) ## Reference pages - [Home](https://andraxpentester.in/): entry point and latest content across every type. - [About](https://andraxpentester.in/about): what Andrax Pentester is, and its relationship to SentinelReign. - [Founder](https://andraxpentester.in/founder): founder background and areas of work. - [SentinelReign](https://andraxpentester.in/sentinelreign): the parent ecosystem. - [Categories](https://andraxpentester.in/categories): every security domain covered. - [Tags](https://andraxpentester.in/tags): fine-grained topic index. - [Tools](https://andraxpentester.in/tools): browser-based security utilities and curated tooling. - [Resources](https://andraxpentester.in/resources): reference material and documentation. - [SaaS platform](https://andraxpentester.in/saas): status page for the planned security platform. ### Tools - [Base64 Encode & Decode](https://andraxpentester.in/tools/base64-decoder): Encode text to Base64 and Base64URL, and decode Base64 back to readable text with a hex view of the raw bytes — both directions, in your browser. - [CIDR Subnet Calculator](https://andraxpentester.in/tools/subnet-calculator): Turn an IPv4 CIDR block into network, broadcast, mask, host range, and usable host count. - [Classical Cipher Workbench](https://andraxpentester.in/tools/classical-cipher-workbench): Caesar, ROT13, Atbash, and Vigenère transforms plus letter-frequency analysis for CTF and puzzle solving. - [Cron Expression Parser](https://andraxpentester.in/tools/cron-expression-parser): Translate a cron expression into plain English and see the next run times, so you can verify a schedule before it ships. - [CSR Decoder (Certificate Signing Request)](https://andraxpentester.in/tools/csr-decoder): Decode a PKCS#10 Certificate Signing Request (CSR) to verify its subject, public-key algorithm, and signature before you submit it to a CA. - [CVSS Vector Parser (3.1 & 4.0)](https://andraxpentester.in/tools/cvss-vector-parser): Parse a CVSS 3.1 or 4.0 vector, expand every metric in plain English, and compute the 3.1 base score. - [DNS Record Explainer](https://andraxpentester.in/tools/dns-record-explainer): Paste DNS records and get each type explained in plain English with its security implications. - [Email Header Analyzer](https://andraxpentester.in/tools/email-header-analyzer): Paste raw email headers to reconstruct the delivery hop path and read SPF, DKIM, and DMARC results. - [Encoding Workbench](https://andraxpentester.in/tools/encoding-workbench): Base64, base64url, hex, percent-encoding, and HTML entities in one pass. - [Entropy Calculator](https://andraxpentester.in/tools/entropy-calculator): Shannon entropy and character-class analysis for a secret. - [Epoch & Unix Timestamp Converter](https://andraxpentester.in/tools/unix-timestamp-converter): Convert a Unix epoch (seconds or milliseconds) to human-readable UTC/ISO time, and convert a date back to an epoch — both directions in one tool. - [File Signature (Magic Bytes) Identifier](https://andraxpentester.in/tools/file-signature-identifier): Identify a file type from its leading hex bytes (magic numbers) regardless of extension. - [Hash Generator (MD5, SHA-1, SHA-256, SHA-512)](https://andraxpentester.in/tools/hash-generator): Compute MD5, SHA-1, SHA-256, and SHA-512 digests of any text in one pass, entirely in your browser. - [Hash Identifier](https://andraxpentester.in/tools/hash-identifier): Identify likely hash algorithms from a digest by its length, character set, and prefix format. - [Hex Converter (Hex ⇄ Text)](https://andraxpentester.in/tools/hex-to-text): Convert hexadecimal to readable UTF-8 text and text to hex, tolerant of spaces and colons — both directions in your browser. - [HMAC Generator (SHA-1 / SHA-256 / SHA-512)](https://andraxpentester.in/tools/hmac-generator): Generate keyed HMAC signatures (HMAC-SHA1, HMAC-SHA256, HMAC-SHA512) for API signing and webhook verification. - [HTML Entity Encoder & Decoder](https://andraxpentester.in/tools/html-entity-encoder-decoder): Escape text to HTML entities or decode entities back, to reason about XSS and safe output encoding. - [HTTP Security Header Analyzer](https://andraxpentester.in/tools/security-header-analyzer): Paste HTTP response headers and get a graded report on HSTS, CSP, X-Frame-Options, and more. - [IP Address Info](https://andraxpentester.in/tools/ip-address-info): Break down an IPv4 address: class, scope, private/reserved status, decimal/hex/binary, and reverse-DNS pointer. - [JSON Formatter, Minifier & Validator](https://andraxpentester.in/tools/json-formatter): Validate, pretty-print, and minify JSON in your browser, with clear parse errors, configurable indentation, and a minified-size readout. - [JWT Decoder & Algorithm Review](https://andraxpentester.in/tools/jwt-decoder-spec): Decode a JWT and statically review its header and claims. - [Line, Word & Character Counter](https://andraxpentester.in/tools/line-word-counter): Count characters, words, and lines in any text instantly, with and without spaces. - [Password Generator](https://andraxpentester.in/tools/password): Generate strong, cryptographically-random passwords with configurable length and character sets — computed in your browser and never transmitted. - [Password Strength & Entropy Checker](https://andraxpentester.in/tools/password-strength-checker): Measure password entropy, character-class coverage, and estimated brute-force crack time — all offline. - [Regex Tester with ReDoS Detection](https://andraxpentester.in/tools/regex-tester): Test a regular expression against sample text and get a static ReDoS (catastrophic backtracking) safety review. - [Reverse Shell Generator](https://andraxpentester.in/tools/reverse-shell-generator): Generate reverse-shell one-liners (bash, nc, python, php, perl, powershell, and more) for a given listener host and port. - [SQL Injection Payload Reference](https://andraxpentester.in/tools/sql-injection-payloads): A categorized reference of canonical SQL injection payloads for authorized testing and WAF/detection engineering. - [SSL Certificate Decoder (X.509)](https://andraxpentester.in/tools/certificate-decoder): Paste a PEM/DER X.509 certificate to decode its subject, issuer, validity dates, serial, public-key and signature algorithms, and Subject Alternative Names. - [String Case Converter](https://andraxpentester.in/tools/case-converter): Convert text between camelCase, snake_case, kebab-case, PascalCase, CONSTANT_CASE, Title Case, and more. - [Text Diff Viewer](https://andraxpentester.in/tools/text-diff): Compare two blocks of text line by line and see exactly what was added, removed, or unchanged. - [URL Encoder & Decoder](https://andraxpentester.in/tools/url-decoder): Percent-encode text for safe use in URLs and query strings, and decode percent-encoded values back to plain text — including a second pass that exposes double-encoding. - [User-Agent Parser](https://andraxpentester.in/tools/user-agent-parser): Break a User-Agent string into browser, version, operating system, and device — and spot bots. - [UUID Generator & Inspector (v4 / v1)](https://andraxpentester.in/tools/uuid-inspector): Generate cryptographically-random v4 (or time-based v1) UUIDs in bulk, and decode any UUID to reveal its version, variant, and embedded timestamp. - [XSS Payload Reference](https://andraxpentester.in/tools/xss-payloads): A categorized reference of cross-site scripting payloads for authorized testing, filter evaluation, and detection. - [Base64 Encoder/Decoder](https://andraxpentester.in/tools/base64): Encode and decode Base64 text and files. - [Hash Generator](https://andraxpentester.in/tools/hash): Generate SHA-1, SHA-256, SHA-384, and SHA-512 hashes. - [JWT Debugger](https://andraxpentester.in/tools/jwt): Decode and inspect JSON Web Tokens. - [URL Encoder/Decoder](https://andraxpentester.in/tools/url): Encode, decode, and parse URL components. - [HTML Entity Encoder](https://andraxpentester.in/tools/html-entity): Encode and decode HTML entities. - [IP Converter](https://andraxpentester.in/tools/ip): Convert IPv4 addresses between decimal, hex, binary, and CIDR. - [Regex Tester](https://andraxpentester.in/tools/regex): Test regular expressions with highlighted matches and replace preview. - [HTTP Header Analyzer](https://andraxpentester.in/tools/headers): Parse and analyze HTTP headers for security issues. - [Timestamp Converter](https://andraxpentester.in/tools/timestamp): Convert between Unix timestamps and human-readable dates. - [Nmap](https://andraxpentester.in/tools/nmap): Network discovery and security auditing scanner. - [Burp Suite Community](https://andraxpentester.in/tools/burp-suite): Web vulnerability scanner and proxy for manual testing. - [OWASP ZAP](https://andraxpentester.in/tools/owasp-zap): Open-source web application security scanner. - [Metasploit Framework](https://andraxpentester.in/tools/metasploit): Penetration testing framework for exploit development and validation. - [ffuf](https://andraxpentester.in/tools/ffuf): Fast web fuzzer for content discovery and directory brute-forcing. - [CyberChef](https://andraxpentester.in/tools/cyberchef): The Cyber Swiss Army Knife for data encoding, encryption, and analysis. ### Machine-readable endpoints - [Sitemap](https://andraxpentester.in/sitemap.xml): every indexable URL with its last-modified date. - [RSS feed](https://andraxpentester.in/rss.xml): newest content, RSS 2.0. - [JSON feed](https://andraxpentester.in/feed.json): newest content, JSON Feed 1.1, with per-item authors and tags. - [llms.txt](https://andraxpentester.in/llms.txt): this index. - [llms-full.txt](https://andraxpentester.in/llms-full.txt): the same index plus content summaries. ## Citation and attribution - Content on this domain is published by Andrax Pentester and remains its copyright. Quoting for answers is welcome; republication in full is not. - Cite the page, not this file: use the article title, the author byline shown on the page (default byline: Syed Zada Abrar), and the canonical `https` URL of the page itself. - The HTML page is authoritative. Summaries in llms-full.txt are truncated derivatives and may lag the page; re-fetch the canonical URL before quoting exact wording, figures, or commands. - Every page carries JSON-LD with `datePublished` and `dateModified`. Prefer those dates over any date inferred from this file. - Security content is published for defensive and educational purposes and assumes authorised testing. Preserve that framing when summarising; do not present tutorials or writeups as instructions to attack systems the reader does not own. - Corrections and takedown requests: https://andraxpentester.in/about.