JonCooperWorks / httpfuzz
☆66Updated 3 years ago
Alternatives and similar repositories for httpfuzz:
Users that are interested in httpfuzz are comparing it to the libraries listed below
- a deterministic finite automata ranker☆70Updated 3 years ago
- ☆31Updated 2 years ago
- HTTP request smuggling attack helper/CLI tools to manipulate HTTP packets☆35Updated 2 years ago
- A PoC code for JSON Smuggling technique to smuggle arbitrary files through JSON☆114Updated last year
- A collection of utilities for building extensions using Burp's Montoya API☆50Updated 9 months ago
- Command line fuzzer and bruteforcer 🌪 wfuzz for command☆85Updated 2 years ago
- Utility for creating ZipSlip archives☆72Updated 2 years ago
- Scalpel is a Burp extension for intercepting and rewriting HTTP traffic, either on the fly or in the Repeater using Python 3 scripts.☆58Updated 10 months ago
- ☆70Updated 3 years ago
- oauth-labs: an intentionally vulnerable set of OAuth 2.0 labs for security training and learning☆67Updated 4 months ago
- A GraphQL enumeration and extraction tool☆131Updated 2 years ago
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆173Updated 5 months ago
- Improve automated and semi-automated active scanning in Burp Pro☆61Updated 2 years ago
- Client-Side Prototype Pollution Tools☆84Updated 3 years ago
- Complex payload encoder☆224Updated last year
- FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application a…☆157Updated 5 months ago
- ☆164Updated 3 years ago
- Find CVE PoCs on GitHub☆147Updated last year
- A simple remote scanner for Atlassian Jira☆120Updated 2 years ago
- ☆94Updated 3 years ago
- Exploit for CVE-2021-25741 vulnerability☆28Updated 3 years ago
- Guided Differential Fuzzing for HTTP Request Parsing Discrepancies☆17Updated last year
- A rapid HTTP downgrade smuggling scanner written in Go.☆254Updated 11 months ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆22Updated last month
- ☆56Updated 3 years ago
- Cloud agnostic IAM permissions enumerator☆147Updated last week
- Intentionally vulnerable Go web app.☆43Updated 2 months ago
- List all public repositories for (valid) GitHub usernames☆73Updated last year
- An extension to use Semgrep inside Burp Suite.☆88Updated last year
- ☆188Updated 5 months ago