ONsec-Lab / SecLists
SecLists is a collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strings, fuzzing payloads, and many more.
☆11Updated 10 years ago
Alternatives and similar repositories for SecLists:
Users that are interested in SecLists are comparing it to the libraries listed below
- Python Implementation of a .NET Padding Oracle Assessment Tool☆30Updated 9 years ago
- [DEPRECATED] Hiccup is a framework that allows the Burp Suite (a web application security testing tool, http://portswigger.net/burp/) to …☆42Updated 6 years ago
- Payload generator for Java Binary Deserialization attack with Commons FileUpload (CVE-2013-2186)☆38Updated 8 years ago
- Spray SMB with hashes, Then psexec☆32Updated 5 years ago
- PHDAYS |||☆17Updated 11 years ago
- Axis2 RPC Shell☆14Updated 9 years ago
- Basic gui to run and display nmap scan results. Just a POC so far.☆31Updated 11 years ago
- Burp plugin to do random fuzzing of HTTP requests☆33Updated 8 years ago
- Vulners signature-base software version detection rules☆37Updated 3 years ago
- Python object interface to requests/responses recorded by Burp Suite☆36Updated 5 years ago
- Simple socket-based gateway to the Burp Collaborator☆33Updated 8 years ago
- XXE OOB Exploitation Toolset for Automation☆63Updated 11 years ago
- Penetration Testing Tools Developed by AppSec Consulting.☆48Updated 6 years ago
- Generates Flash based CORS CSRF Proof of Concepts that can be sent directly to clients☆14Updated 11 years ago
- ActionScript Proof of Concept to perform cross-domain reads☆16Updated 11 years ago
- Updated version of SWFIntruder☆26Updated 8 years ago
- This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB …☆22Updated 5 years ago
- An adaptive, intelligent XSS fuzzer that learns how the response is reflected and carefully crafts an XSS payload to match☆42Updated 12 years ago
- ☆46Updated 7 years ago
- ISR-sqlget It's a blind SQL injection tool developed in Perl.☆14Updated 11 years ago
- ☆70Updated 7 years ago
- Faraday Continuous Scanning☆33Updated 8 years ago
- A proof of concept that demonstrates asynchronous scanning for Java deserialization bugs☆54Updated 7 years ago
- SharePoint scanner and fingerprinter based on WPScan☆25Updated 11 years ago
- BurpSuite extension to assist with Automated Forced Browsing/Endpoint Enumeration☆22Updated 6 years ago
- Scan web server for known webshell names and responses☆50Updated 8 years ago
- misc pentest tools.☆26Updated 10 years ago
- Files from Zeronights presentation.☆28Updated 12 years ago
- CVE-2017-8570 Exploit☆21Updated 7 years ago
- Materials related to the 2017 BSides Las Vegas presentation☆51Updated 4 years ago