PortSwigger / asset-discoveryLinks
Burp Suite extension to discover assets from HTTP response.
☆16Updated 4 years ago
Alternatives and similar repositories for asset-discovery
Users that are interested in asset-discovery are comparing it to the libraries listed below
Sorting:
- ☆36Updated 10 months ago
- Local File Inclusion Burp-Suite Intruder Payload Generator Plugin☆40Updated 5 years ago
- Burp extension that checks application requests and responses for indicators of vulnerability or targets for attack☆41Updated 2 years ago
- Nmap script to check vulnerability CVE-2021-21975☆28Updated 4 years ago
- A simple tool to detect wildcards domain based on Amass's wildcards detector.☆65Updated 4 years ago
- The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.☆77Updated 5 years ago
- This is the Go Server that relays all HTTP requests and responses between clients.☆28Updated 2 years ago
- RCE for Pega Infinity >= 8.2.1, Pega Infinity <= 8.5.2☆60Updated 4 years ago
- SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing☆90Updated 5 years ago
- Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities☆46Updated 2 years ago
- Image Tragick Exploit Tool Using Burp Collaborator☆37Updated last year
- BurpSuite's payload-generation extension aiming at applying fuzzed test-cases depending on the type of payload (integer, string, path; JS…☆40Updated 4 years ago
- ☆22Updated 3 years ago
- Collection of content discovery wordlists in one wordlist.☆38Updated 3 years ago
- Hacked together script for feeding urls into Burp's Sitemap☆93Updated 6 months ago
- Messy BurpSuite plugin for SQL Truncation vulnerabilities.☆63Updated 5 years ago
- Spring Boot Actuator (jolokia) XXE/RCE☆24Updated 6 years ago
- The original slurp source☆33Updated 6 years ago
- A bash script that automates the scanning of a target network for HTTP resources through XXE☆38Updated 4 years ago
- Get all possible href | src | url from target url or domain☆41Updated 5 years ago
- A Web-UI for subdomain enumeration (subfinder)☆55Updated 5 years ago
- Unique wordlist generator of unique wordlists.☆42Updated 2 years ago
- Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.☆48Updated 4 years ago
- Writeup of CVE-2020-15906☆49Updated 5 years ago
- Default plugins for Jaeles Scanner☆35Updated 5 years ago
- Just a simple SMTP server, implementation of @corpix smtpd library☆15Updated 5 years ago
- JavaScript functions intended to be used as an XSS payload against a WordPress admin account.☆56Updated 5 years ago
- DO NOT RUN THIS.☆47Updated 4 years ago
- "Powershell script assisting with domain enumerating and in finding quick wins" - Basically written while doing the 'Advanced Red Team' l…☆82Updated 4 years ago
- Kubernetes Scanner☆40Updated 3 years ago