Stars
JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.
🐍 A toolkit for testing, tweaking and cracking JSON Web Tokens
一个想让你测试加密流量像测试明文一样简单高效的 Burp 插件。 A Burp plugin that makes testing encrypted traffic as simple and efficient as testing plaintext.
The Leading Security Assessment Framework for Android.
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static a…
A Magisk/KernelSU module that automatically adds user certificates to the system root CA store
An xposed module that disables SSL certificate checking for the purposes of auditing an app with cert pinning
Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。
xia SQL (瞎注) burp 插件 ,在每个参数后面填加一个单引号,两个单引号,一个简单的判断注入小插件。
Log4j2 RCE Passive Scanner plugin for BurpSuite
一款完全被动监听的谷歌插件,用于高危指纹识别、蜜罐特征告警和拦截、机器特征对抗
Scan for sensitive information easily and effectively.
ShiroExploit 是一款 Shiro 可视化利用工具,集成密钥爆破,命令回显内存马注入等功能
超级弱口令检查工具是一款Windows平台的弱口令审计工具,支持批量多线程检查,可快速发现弱密码、弱口令账号,密码支持和用户名结合进行检查,大大提高成功率,支持自定义服务端口和字典。
A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.
针对SpringBoot的开源渗透框架,以及Spring相关高危漏洞利用工具
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…