ONsec-Lab / SecListsLinks
SecLists is a collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strings, fuzzing payloads, and many more.
☆11Updated 10 years ago
Alternatives and similar repositories for SecLists
Users that are interested in SecLists are comparing it to the libraries listed below
Sorting:
- Payload generator for Java Binary Deserialization attack with Commons FileUpload (CVE-2013-2186)☆38Updated 9 years ago
- Python Implementation of a .NET Padding Oracle Assessment Tool☆30Updated 9 years ago
- Burp plugin to do random fuzzing of HTTP requests☆33Updated 8 years ago
- REST/JSON interface to Burp Suite☆33Updated 4 years ago
- ☆10Updated 9 years ago
- PHDAYS |||☆17Updated 12 years ago
- ActionScript Proof of Concept to perform cross-domain reads☆16Updated 11 years ago
- ☆23Updated 10 years ago
- Simple socket-based gateway to the Burp Collaborator☆33Updated 8 years ago
- XXE OOB Exploitation Toolset for Automation☆63Updated 11 years ago
- ☆23Updated 9 years ago
- A quick and dirty .NET "Deserialize_*" fuzzer based on James Forshaw's (@tiraniddo) DotNetToJScript.☆42Updated 6 years ago
- Modified version of ActiveScan++ Burp Suite extension☆31Updated 8 years ago
- Spray SMB with hashes, Then psexec☆32Updated 5 years ago
- Updated version of SWFIntruder☆26Updated 8 years ago
- Tainted PhantomJS☆52Updated 9 years ago
- Burp extension that checks for interesting and security headers☆43Updated 4 years ago
- Axis2 RPC Shell☆15Updated 9 years ago
- A modular distributed penetration testing tool.☆41Updated 8 years ago
- Demonstrating why Dynamic Method Invocation with unrestricted method names (the old default of Struts) is dangerous.☆12Updated 6 years ago
- Some exploits for ZeroNights 0x03☆36Updated 9 years ago
- Generates Flash based CORS CSRF Proof of Concepts that can be sent directly to clients☆14Updated 11 years ago
- Burp Extender to add unique form tokens to scanner requests.☆14Updated 7 months ago
- Scan web server for known webshell names and responses☆50Updated 8 years ago
- BlackHat Europe 2017 Slides☆26Updated 7 years ago
- Basic gui to run and display nmap scan results. Just a POC so far.☆31Updated 11 years ago
- Study about HQL injection exploitation.☆51Updated 9 years ago
- ☆70Updated 7 years ago
- CVE-2017-8570 Exploit☆21Updated 7 years ago
- ISR-sqlget It's a blind SQL injection tool developed in Perl.☆14Updated 12 years ago