Lists (1)
Sort Name ascending (A-Z)
Stars
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
Automatic SQL injection and database takeover tool
fsociety Hacking Tools Pack – A Penetration Testing Framework
You Know, For WEB Fuzzing ! 日站用的字典。
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
Automated All-in-One OS Command Injection Exploitation Tool.
A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference
Server-Side Template Injection and Code Injection Detection and Exploitation Tool
A python script that finds endpoints in JavaScript files
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws
Automated NoSQL database enumeration and web application exploitation tool.
Detect and bypass web application firewalls and protection systems
Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.
Obtain GraphQL API schema even if the introspection is disabled
Automatic SSTI detection tool with interactive interface
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automa…
Nuclei Templates Collection
A python script to scan for Apache Tomcat server vulnerabilities.
This repository contains all the supplement material for the book "The art of sub-domain enumeration"
graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.