Awesome information for WebSockets security research
☆301Jan 10, 2022Updated 4 years ago
Alternatives and similar repositories for awesome-websocket-security
Users that are interested in awesome-websocket-security are comparing it to the libraries listed below
Sorting:
- Jumpstart multiple WebSocket servers quickly☆32Nov 23, 2021Updated 4 years ago
- A Security Tool for Enumerating WebSockets☆366Jan 10, 2022Updated 4 years ago
- Supporting material for the "Hunting Bugs In The Tropics" DEFCON 30 talk☆10Aug 18, 2022Updated 3 years ago
- A fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀☆659Aug 28, 2025Updated 6 months ago
- bypass-url-parser☆1,115Updated this week
- Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load☆296Sep 22, 2024Updated last year
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆953Dec 31, 2021Updated 4 years ago
- A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the communit…☆3,645Nov 23, 2025Updated 3 months ago
- Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist☆1,500Jan 8, 2026Updated last month
- A repository that includes all the important wordlists used while bug hunting.☆1,379Mar 11, 2023Updated 2 years ago
- ☆1,200Sep 2, 2022Updated 3 years ago
- One liner regex match to search inside JS files, using curl and grep!☆29Dec 26, 2021Updated 4 years ago
- De-clutter a list of URLs☆385Feb 3, 2026Updated last month
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆176Oct 26, 2024Updated last year
- Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hac…☆1,153Jan 21, 2026Updated last month
- 🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast…☆1,519Updated this week
- A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets☆1,529Jan 15, 2026Updated last month
- ☆159Jan 7, 2022Updated 4 years ago
- A simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issues☆374Jul 25, 2023Updated 2 years ago
- Automatic SSRF fuzzer and exploitation tool☆3,489Sep 4, 2025Updated 6 months ago
- ☆34Jun 23, 2021Updated 4 years ago
- Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!☆978Jan 12, 2024Updated 2 years ago
- Prototype Pollution and useful Script Gadgets☆1,589Jan 27, 2024Updated 2 years ago
- simple recon tool to help you for searching vulnerability on web server☆75Dec 30, 2025Updated 2 months ago
- mx-takeover focuses DNS MX records and detects misconfigured MX records.☆357Jul 17, 2023Updated 2 years ago
- Python's handling of NaN is....interesting?broken?...this project illustrates the issue☆13Dec 28, 2021Updated 4 years ago
- Smart context-based SSRF vulnerability scanner.☆360May 5, 2022Updated 3 years ago
- ☆300Dec 9, 2022Updated 3 years ago
- Mind-Maps of Several Things☆2,625Jun 29, 2023Updated 2 years ago
- A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.☆1,977Sep 5, 2021Updated 4 years ago
- Tools & Interesting Things for RedTeam Ops☆2,258Feb 10, 2026Updated 3 weeks ago
- A toolkit for testing, tweaking and cracking JSON Web Tokens☆6,402May 1, 2025Updated 10 months ago
- Let's check if your target is vulnerable for client side prototype pollution.☆65Jan 9, 2024Updated 2 years ago
- Hidden parameters discovery suite☆2,028Sep 8, 2024Updated last year
- Content-Type Research☆656Jun 29, 2025Updated 8 months ago
- A cheat sheet that contains advanced queries for SQL Injection of all types.☆3,154May 13, 2023Updated 2 years ago
- Asset inventory of over 800 public bug bounty programs.☆1,520Feb 14, 2025Updated last year
- GraphQL automated security testing toolkit☆333Feb 20, 2024Updated 2 years ago
- 🕵️ Python project to crawl for JavaScript files and search for secrets like API keys, authorization tokens, hardcoded credentials, etc.☆429May 15, 2025Updated 9 months ago