PortSwigger / burp-extensions-montoya-api
Burp Extensions Api
☆139Updated this week
Related projects ⓘ
Alternatives and complementary repositories for burp-extensions-montoya-api
- Examples for using the Montoya API with Burp Suite☆114Updated 11 months ago
- ☆170Updated 3 weeks ago
- Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.☆185Updated 5 months ago
- jolokia-exploitation-toolkit☆281Updated 8 months ago
- Burp Extension for a passive scanning JS files for endpoint links.☆162Updated 5 years ago
- ☆398Updated 2 years ago
- Burp Suite Extension - Trigger actions and reshape HTTP request/response and WebSocket traffic using configurable rules☆92Updated 2 weeks ago
- Burpsuite plugin for Interact.sh☆198Updated 4 months ago
- JMX enumeration and attacking tool.☆395Updated last month
- Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease appli…☆220Updated 2 months ago
- This is the data that powers the PortSwigger URL validation bypass cheat sheet.☆30Updated last month
- CVE-2022-44268 ImageMagick Arbitrary File Read - Payload Generator☆270Updated last year
- ☆71Updated 6 months ago
- A collection of Server-Side Prototype Pollution gadgets and exploits☆134Updated 2 months ago
- This tool is for letting you know how strong your disable_functions is and how you can bypass that.☆113Updated 5 years ago
- Subdomains analysis and generation tool. Reveal the hidden!☆232Updated last week
- Bambdas collection for Burp Suite Professional and Community.☆206Updated 3 weeks ago
- HopLa Burp Suite Extender plugin - Adds autocompletion support and useful payloads in Burp Suite☆712Updated 3 years ago
- Nuclei Templates to reproduce Cracking the lens's Research☆121Updated 2 years ago
- This repo contains all the injections mentioned in my talk and enumerators.☆121Updated 11 months ago
- CVE-2024-4367 & CVE-2024-34342 Proof of Concept☆136Updated 5 months ago
- A rapid HTTP downgrade smuggling scanner written in Go.☆246Updated 6 months ago
- A Burp extension helps identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations,…☆354Updated last month
- Finding Java gadget chains with CodeQL☆159Updated 3 months ago
- A CLI to exploit parameters vulnerable to PHP filter chain error based oracle.☆228Updated 5 months ago
- Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.☆177Updated last month
- Burp Suite extension for bypassing client-side encryption for pentesting and bug bounty☆186Updated 4 months ago
- SSRF plugin for burp Automates SSRF Detection in all of the Request☆555Updated 3 years ago
- jws2pubkey tool☆37Updated 5 months ago
- Same Origin XSS challenge☆56Updated 2 years ago