0xspade / Combined-Wordlists
A combined wordlists for files and directory discovery
☆117Updated 3 years ago
Alternatives and similar repositories for Combined-Wordlists:
Users that are interested in Combined-Wordlists are comparing it to the libraries listed below
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆130Updated 3 years ago
- Generates target specific word lists for Fuzzing with fuff☆107Updated 4 years ago
- All known and unknown public POC's for wordpress themes and plugins☆79Updated 3 years ago
- Various Payload wordlists☆235Updated 4 years ago
- 📚 An ultimate collection wordlists of the best-known CMS☆85Updated 7 months ago
- BurpSuite extension to inject custom cross-site scripting payloads on every form/request submitted to detect blind XSS vulnerabilities☆110Updated last year
- golang tool to scan domains or single domains with know security issues against xmlrpc☆60Updated last year
- A simple Bash one liner with aim to automate CRLF vulnerability scanning.☆68Updated 4 years ago
- This Repo contains wordlist for subdomain enumeration , php file path, html file path, and js file path☆103Updated 4 years ago
- Searching for virtual hosts among non-resolvable domains☆87Updated 4 years ago
- Match and Replace script used to automatically generate JSON option file to BurpSuite☆213Updated 5 years ago
- Small tool to automate SSRF wordpress and XMLRPC finder☆80Updated 2 years ago
- Bug Bounty stuffs, payloads, scripts, profiles, tips and tricks, ...☆145Updated 4 years ago
- ☆29Updated 3 years ago
- A reverse whois tool based on Whoxy API.☆161Updated 9 months ago
- Prototype Pollution Scanner☆106Updated 3 years ago
- A tool for append URLs, skipping duplicates/paths & combine parameters.☆120Updated 2 years ago
- CRLF and open redirect fuzzer☆112Updated 3 years ago
- LFI Payloads List coolected from github repos☆72Updated 4 years ago
- ASN reconnaissance script☆124Updated last year
- HTTP parameter discovery suite.☆94Updated 4 years ago
- Dotmil subdomain discovery tool that scrapes domains from official DoD website directories and certificate transparency logs☆96Updated 4 years ago
- Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, al…☆176Updated 4 years ago
- This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.☆162Updated 3 years ago
- A docker image which will enumerate, sort, unique and resolve the results of various subdomains enumeration tools.☆70Updated 6 months ago
- Wwwordlist is a wordlist generator for pentesters and bug bounty hunters. It extracts words from HTML, URLs, JS/HTTP/input variables, quo…☆101Updated last year
- ☆76Updated 4 years ago
- Pass list of urls with FUZZ in and it will check if it has found a potential SSRF.☆106Updated 2 years ago
- Horizontal Domain Discovery☆75Updated last year
- The scripts I write to help me on my bug bounty hunting☆121Updated 3 years ago