Ekultek / WhatWaf
Detect and bypass web application firewalls and protection systems
☆2,667Updated 3 months ago
Related projects ⓘ
Alternatives and complementary repositories for WhatWaf
- File upload vulnerability scanner and exploitation tool.☆3,053Updated last year
- WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.☆5,300Updated last month
- Web application fuzzer☆5,968Updated 3 months ago
- HTTP parameter discovery suite.☆5,280Updated 2 weeks ago
- Automated NoSQL database enumeration and web application exploitation tool.☆2,929Updated 3 months ago
- A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and…☆3,684Updated 3 years ago
- Automated All-in-One OS Command Injection Exploitation Tool.☆4,613Updated this week
- The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, su…☆3,332Updated 9 months ago
- A python script that finds endpoints in JavaScript files☆3,724Updated 7 months ago
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆3,794Updated 6 months ago
- A Tool for Domain Flyovers☆5,644Updated 2 years ago
- A Workflow Engine for Offensive Security☆5,344Updated 5 months ago
- Striker is an offensive information and vulnerability scanner.☆2,234Updated last year
- Automatic SSRF fuzzer and exploitation tool☆3,000Updated 5 months ago
- A collection of custom security tools for quick needs.☆3,152Updated last year
- CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs☆2,328Updated 7 months ago
- EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.☆4,996Updated 3 weeks ago
- A curated list of amazingly awesome Burp Extensions☆3,000Updated this week
- A high performance offensive security tool for reconnaissance and vulnerability scanning☆3,091Updated 5 months ago
- 🔥 Web-application firewalls (WAFs) from security standpoint.☆6,326Updated 3 weeks ago
- Bruteforcing from various scanner output - Automatically attempts default creds on found services.☆2,043Updated last week
- Git All the Payloads! A collection of web attack payloads.☆3,630Updated last year
- Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network☆2,243Updated 7 months ago
- Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner☆1,699Updated 2 years ago
- The Swiss Army knife for automated Web Application Testing☆2,166Updated 6 months ago
- Advanced vulnerability scanning with Nmap NSE☆3,479Updated 2 months ago
- Find web directories without bruteforce☆1,772Updated last year
- A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)☆3,173Updated 8 months ago
- SSRF (Server Side Request Forgery) testing resources☆2,352Updated last month
- Subdomain Takeover tool written in Go☆1,911Updated last year