DontPanicO / jwtXploiterView external linksLinks
A tool to test security of json web token
☆286Mar 12, 2021Updated 4 years ago
Alternatives and similar repositories for jwtXploiter
Users that are interested in jwtXploiter are comparing it to the libraries listed below
Sorting:
- Get all the CNs from a list of domains☆45Aug 17, 2021Updated 4 years ago
- goverview - Get an overview of the list of URLs☆143Dec 5, 2025Updated 2 months ago
- A tool that turns the authoritative nameservers of DNS providers to resolvers and resolves the target domain list. Please think of this a…☆25Sep 19, 2019Updated 6 years ago
- A collection of code for interacting with API sources directly to improve your understanding of those services.☆66Dec 11, 2020Updated 5 years ago
- Cross Origin Resource Sharing MisConfiguration Scanner☆173Nov 17, 2021Updated 4 years ago
- Static code analysis tool based on Elasticsearch☆129Jan 23, 2021Updated 5 years ago
- Prototype pollution scanner using headless chrome☆219Jul 27, 2022Updated 3 years ago
- HTTP Request Smuggling Detection Tool☆535Dec 21, 2023Updated 2 years ago
- JSON Web Token Hack Toolkit☆972Updated this week
- Smart ssrf scanner using different methods like parameter brute forcing in post and get...☆280Feb 11, 2021Updated 5 years ago
- Tool to check for dependency confusion vulnerabilities in multiple package management systems☆775Aug 19, 2024Updated last year
- Security Testing Scripts for JWT☆327Jun 30, 2022Updated 3 years ago
- Scrape domain names from SSL certificates of arbitrary hosts☆689Mar 31, 2024Updated last year
- SSRF plugin for burp Automates SSRF Detection in all of the Request☆610Jan 20, 2021Updated 5 years ago
- Hidden parameters discovery suite☆2,015Sep 8, 2024Updated last year
- Second-order subdomain takeover scanner☆406Aug 28, 2025Updated 5 months ago
- Automation for javascript recon in bug bounty.☆1,067Sep 9, 2023Updated 2 years ago
- Command line tool for testing CRLF injection on a list of domains.☆166Apr 14, 2024Updated last year
- A tool to find redirection chains in multiple URLs☆78Jan 1, 2025Updated last year
- Making Favicon.ico based Recon Great again !☆1,261Aug 29, 2023Updated 2 years ago
- a javascript change monitoring tool for bugbounties☆710Jul 31, 2024Updated last year
- A toolkit for testing, tweaking and cracking JSON Web Tokens☆6,357May 1, 2025Updated 9 months ago
- A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.☆519Jun 22, 2022Updated 3 years ago
- gup aka Get All Urls parameters to create wordlists for brute forcing parameters.☆18Dec 4, 2021Updated 4 years ago
- Takeover subdomains using AWS dangling elastic ips and have a working POC for Subdomain Takeover.☆93Jul 9, 2025Updated 7 months ago
- Customisable and automated HTTP header injection☆270Jun 27, 2024Updated last year
- Horizontal Domain Discovery☆77May 22, 2023Updated 2 years ago
- Open Redirection Analyzer☆811Mar 5, 2023Updated 2 years ago
- A tool to fastly get all javascript sources/files☆856Jul 4, 2025Updated 7 months ago
- A bash script that automates the scanning of a target network for HTTP resources through XXE☆37Dec 2, 2020Updated 5 years ago
- bypass-url-parser☆1,111Feb 7, 2026Updated last week
- Secret and/or credential patterns used for gf.☆243Feb 10, 2023Updated 3 years ago
- Wordlist to bruteforce for LFI☆128Oct 6, 2019Updated 6 years ago
- A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..e…☆1,021Jun 24, 2024Updated last year
- 40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...☆1,807Jul 3, 2023Updated 2 years ago
- ☆59Apr 8, 2021Updated 4 years ago
- A fast tool to fetch URLs from HTML attributes by crawl-in.☆261Jan 23, 2025Updated last year
- SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files☆2,376May 26, 2024Updated last year
- Urls status code & content length checker☆146Oct 1, 2020Updated 5 years ago