PortSwigger / asset-discoveryLinks
Burp Suite extension to discover assets from HTTP response.
☆16Updated 4 years ago
Alternatives and similar repositories for asset-discovery
Users that are interested in asset-discovery are comparing it to the libraries listed below
Sorting:
- Local File Inclusion Burp-Suite Intruder Payload Generator Plugin☆40Updated 4 years ago
- ☆36Updated 6 months ago
- Burp extension that checks application requests and responses for indicators of vulnerability or targets for attack☆41Updated 2 years ago
- A simple tool to detect wildcards domain based on Amass's wildcards detector.☆65Updated 4 years ago
- Nmap script to check vulnerability CVE-2021-21975☆28Updated 4 years ago
- This is the Go Server that relays all HTTP requests and responses between clients.☆27Updated last year
- The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.☆77Updated 4 years ago
- Image Tragick Exploit Tool Using Burp Collaborator☆36Updated last year
- Messy BurpSuite plugin for SQL Truncation vulnerabilities.☆63Updated 5 years ago
- ☆22Updated 3 years ago
- RCE for Pega Infinity >= 8.2.1, Pega Infinity <= 8.5.2☆60Updated 4 years ago
- SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing☆91Updated 5 years ago
- ☆47Updated 4 years ago
- Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities☆46Updated 2 years ago
- A bash script that automates the scanning of a target network for HTTP resources through XXE☆38Updated 4 years ago
- Hacked together script for feeding urls into Burp's Sitemap☆93Updated 3 months ago
- Writeup of CVE-2020-15906☆48Updated 4 years ago
- Collection of content discovery wordlists in one wordlist.☆38Updated 3 years ago
- A Web-UI for subdomain enumeration (subfinder)☆54Updated 5 years ago
- BurpSuite's payload-generation extension aiming at applying fuzzed test-cases depending on the type of payload (integer, string, path; JS…☆41Updated 4 years ago
- JavaScript functions intended to be used as an XSS payload against a WordPress admin account.☆54Updated 4 years ago
- Unique wordlist generator of unique wordlists.☆42Updated 2 years ago
- Just a simple SMTP server, implementation of @corpix smtpd library☆15Updated 5 years ago
- Default plugins for Jaeles Scanner☆34Updated 4 years ago
- CVE-2020-9484 Mass Scanner, Scan a list of urls for Apache Tomcat deserialization (CVE-2020-9484) which could lead to RCE☆32Updated 5 years ago
- A Burp Suite extension for headless, unattended scanning.☆36Updated 5 years ago
- BurpSuite Extension: A one-stop pen testing checklist and logger tool☆75Updated 2 years ago
- DO NOT RUN THIS.☆47Updated 3 years ago
- Get all possible href | src | url from target url or domain☆41Updated 5 years ago
- ☆26Updated 3 years ago