MindPatch / lorsrf
Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load
☆289Updated last month
Related projects ⓘ
Alternatives and complementary repositories for lorsrf
- Customisable and automated HTTP header injection☆237Updated 4 months ago
- Prototype pollution scanner using headless chrome☆197Updated 2 years ago
- Nuclei templates written by us.☆265Updated 3 years ago
- Burp extension to create target specific and tailored wordlist from burp history.☆231Updated 2 years ago
- List of reporting templates I have used since I started doing BBH.☆234Updated last month
- Finding XSS during recon☆248Updated 2 years ago
- ☆285Updated 2 years ago
- Gotator is a tool to generate DNS wordlists through permutations.☆453Updated 2 years ago
- Full Nuclei automation script with logic explanation.☆236Updated 2 years ago
- Monitoring framework to detect and report newly found subdomains on a specific target using various scanning tools☆265Updated 3 months ago
- ☆144Updated last year
- A replacement of "qsreplace", accepts URLs as standard input, replaces all query string values with user-supplied values and stdout.☆102Updated 2 years ago
- Secret and/or credential patterns used for gf.☆233Updated last year
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆295Updated last year
- ☆146Updated last year
- Bug Bounty stuffs, payloads, scripts, profiles, tips and tricks, ...☆145Updated 4 years ago
- Pass in a list of URLs with query strings, get back a unique list of URLs and query string combinations☆337Updated 4 years ago
- List of fresh DNS resolvers updated daily☆106Updated last year
- Burpsuite plugin for Interact.sh☆198Updated 4 months ago
- Burp Extension for easily creating Wordlists☆210Updated 3 years ago
- Js File Scanner☆160Updated 2 years ago
- Nuclei Templates - Here you will find the templates I use while hunting☆116Updated 3 years ago
- Domains belonging to the most reputed public bug bounty programs. [NOT FOR NON-MONETARY OR PRIVATE PROGRAMS]☆214Updated 2 months ago
- Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, al…☆175Updated 3 years ago
- This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.☆162Updated 3 years ago
- Automated tool for domains & subdomains gathering☆179Updated last year
- Check AWS S3 instances for read/write/delete access☆121Updated 2 years ago
- A reverse whois tool based on Whoxy API.☆158Updated 7 months ago