Ekultek / WhatWaf
Detect and bypass web application firewalls and protection systems
☆2,739Updated 7 months ago
Alternatives and similar repositories for WhatWaf:
Users that are interested in WhatWaf are comparing it to the libraries listed below
- WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.☆5,567Updated 2 months ago
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆3,892Updated 11 months ago
- File upload vulnerability scanner and exploitation tool.☆3,180Updated last year
- A Tool for Domain Flyovers☆5,732Updated 2 years ago
- HTTP parameter discovery suite.☆5,520Updated last month
- Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications…☆1,278Updated 6 months ago
- A curated list of amazingly awesome Burp Extensions☆3,105Updated last month
- A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)☆3,293Updated 2 months ago
- Automatic SSRF fuzzer and exploitation tool☆3,126Updated last month
- Generates permutations, alterations and mutations of subdomains and then resolves them☆2,393Updated 2 months ago
- SSRF (Server Side Request Forgery) testing resources☆2,395Updated 5 months ago
- A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and…☆3,766Updated 3 years ago
- CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs☆2,385Updated 11 months ago
- Automated NoSQL database enumeration and web application exploitation tool.☆3,029Updated 7 months ago
- Striker is an offensive information and vulnerability scanner.☆2,261Updated last year
- Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner☆1,773Updated 2 years ago
- The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, su…☆3,427Updated last year
- A Workflow Engine for Offensive Security☆5,522Updated last month
- Bruteforcing from various scanner output - Automatically attempts default creds on found services.☆2,179Updated this week
- A python script that finds endpoints in JavaScript files☆3,867Updated 11 months ago
- Weaponized web shell☆3,277Updated 5 months ago
- Automated All-in-One OS Command Injection Exploitation Tool.☆5,188Updated last week
- Knock Subdomain Scan☆3,958Updated 4 months ago
- EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.☆5,219Updated 5 months ago
- Git All the Payloads! A collection of web attack payloads.☆3,695Updated last year
- HackBar plugin for Burpsuite☆1,563Updated 3 years ago
- The XSS Hunter service - a portable version of XSSHunter.com☆1,514Updated 2 years ago
- Advanced vulnerability scanning with Nmap NSE☆3,578Updated 6 months ago
- A toolkit for testing, tweaking and cracking JSON Web Tokens☆5,675Updated 7 months ago
- A high performance offensive security tool for reconnaissance and vulnerability scanning☆3,160Updated 9 months ago