PortSwigger / co2Links
A collection of enhancements for Portswigger's popular Burp Suite web penetration testing tool.
☆24Updated last year
Alternatives and similar repositories for co2
Users that are interested in co2 are comparing it to the libraries listed below
Sorting:
- Add headers to all Burp requests to bypass some WAF products☆44Updated 2 years ago
- Messy BurpSuite plugin for SQL Truncation vulnerabilities.☆63Updated 5 years ago
- Hacked together script for feeding urls into Burp's Sitemap☆93Updated 2 months ago
- The objective of this Burp Suite extension is the flexible and dynamic extraction, correlation, and structured presentation of informatio…☆60Updated 3 years ago
- All known and unknown public POC's for wordpress themes and plugins☆78Updated 4 years ago
- Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities☆49Updated 3 years ago
- Host Header Injection Scanner☆50Updated 5 years ago
- golang tool to scan domains or single domains with know security issues against xmlrpc☆62Updated 2 years ago
- Security test tool for Blind XSS☆26Updated 5 years ago
- SQLi Query Tampering extends and adds custom Payload Generator/Processor in Burp Suite's Intruder. This extension gives you the flexibil…☆156Updated 5 years ago
- A simple Bash one liner with aim to automate CRLF vulnerability scanning.☆69Updated 5 years ago
- ☆42Updated 2 years ago
- ☆11Updated 3 years ago
- SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files☆35Updated 5 years ago
- Virtual host wordlist☆51Updated 5 years ago
- Literally spray blind xss payloads everywhere.☆26Updated 3 years ago
- Converts a hostname (or URI) to IP address using your local resolver☆26Updated last year
- Burp extension that checks application requests and responses for indicators of vulnerability or targets for attack☆41Updated 3 years ago
- A Web-UI for subdomain enumeration (subfinder)☆56Updated 5 years ago
- 0x0p1n3r is set of combination of other tools and one line scripts to find subdomains easily and to check subdomain takeover☆57Updated 5 years ago
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆59Updated 4 years ago
- Get all possible href | src | url from target url or domain☆40Updated 5 years ago
- A Payload Injector for bugbounties written in go☆70Updated 5 years ago
- Tool to automate recon☆42Updated 4 years ago
- XSS scanning with Dalfox on Github-action☆26Updated 2 years ago
- SubzzZ to find possible subdomains using passive recon. Tool also support Permutations, Mutations, Alterations.☆38Updated 4 years ago
- ☆59Updated 4 years ago
- Extract endpoints marked as disallow in robots files to generate wordlists.☆58Updated 3 years ago
- Subvenkon is a subdomain enumerator from Venkon☆23Updated 5 years ago
- Offsec Pentest and Bug Bounty Notes☆25Updated 5 years ago