MindPatch / lorsrf
Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load
☆294Updated 4 months ago
Alternatives and similar repositories for lorsrf:
Users that are interested in lorsrf are comparing it to the libraries listed below
- Secret and/or credential patterns used for gf.☆238Updated 2 years ago
- Customisable and automated HTTP header injection☆243Updated 7 months ago
- Nuclei templates written by us.☆266Updated 3 years ago
- Burp Extension for easily creating Wordlists☆210Updated 3 years ago
- ☆285Updated 2 years ago
- Prototype pollution scanner using headless chrome☆216Updated 2 years ago
- Bug Bounty stuffs, payloads, scripts, profiles, tips and tricks, ...☆145Updated 4 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆130Updated 3 years ago
- A replacement of "qsreplace", accepts URLs as standard input, replaces all query string values with user-supplied values and stdout.☆104Updated 2 years ago
- Nuclei Templates - Here you will find the templates I use while hunting☆117Updated 3 years ago
- Urls de-duplication tool for better recon.☆138Updated 7 months ago
- A reverse whois tool based on Whoxy API.☆162Updated 10 months ago
- Gotator is a tool to generate DNS wordlists through permutations.☆465Updated 2 years ago
- Pass in a list of URLs with query strings, get back a unique list of URLs and query string combinations☆349Updated 4 years ago
- Burpsuite plugin for Interact.sh☆204Updated 7 months ago
- A blind XSS detection and XSS data capture framework☆170Updated last week
- Js File Scanner☆167Updated 3 years ago
- Burp extension to create target specific and tailored wordlist from burp history.☆234Updated 3 years ago
- ☆152Updated last year
- List of reporting templates I have used since I started doing BBH.☆247Updated 4 months ago
- This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.☆163Updated 3 years ago
- Check AWS S3 instances for read/write/delete access☆120Updated 3 years ago
- Monitoring framework to detect and report newly found subdomains on a specific target using various scanning tools☆272Updated 7 months ago
- Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, al…☆176Updated 4 years ago
- ☆151Updated last year
- Full Nuclei automation script with logic explanation.☆244Updated 2 years ago
- List of fresh DNS resolvers updated daily☆109Updated 2 years ago
- IP Lookups for Open Ports and Vulnerabilities from internetdb.shodan.io☆126Updated 2 years ago
- CRLF and open redirect fuzzer☆113Updated 3 years ago
- The scripts I write to help me on my bug bounty hunting☆121Updated 3 years ago