PortSwigger / sensitive-discoverer
Introduction to CYS4-SensitiveDiscoverer, a Burp extension that discovers sensitive information inside HTTP messages.
☆17Updated 3 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for sensitive-discoverer
- Burp Extension that lets you use Burp Collaborator as a DNS server for exfiltrating data via Sqlmap☆36Updated 3 years ago
- tool that generates bypasses for open redirects☆49Updated 2 years ago
- PoC for CVE-2021-45897☆18Updated 2 years ago
- A burp-suite plugin that extract all parameter names from in-scope requests☆29Updated 3 years ago
- cve-2022-42889 Text4Shell CVE-2022-42889 affects Apache Commons Text versions 1.5 through 1.9. It has been patched as of Commons Text ver…☆37Updated 2 years ago
- Oracle WebLogic CVE-2022-21371☆17Updated 2 years ago
- Find sources and sinks in js code that could lead to DOM XSS 🔎💧🚰☆22Updated 8 months ago
- ☆32Updated 2 years ago
- CVE-2022-24112:Apache APISIX apisix/batch-requests RCE☆44Updated 2 years ago
- ☆24Updated 5 months ago
- A fingerprint generation helper for nuclei network templates☆72Updated 2 years ago
- [CVE-2020-14882] Oracle WebLogic Server Authenticated Remote Code Execution (RCE)☆13Updated 4 years ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆27Updated last year
- ☆29Updated 7 months ago
- Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers.☆36Updated last year
- CVE-2022-1388 F5 BIG-IP iControl REST RCE☆35Updated 2 years ago
- Exploit for CVE-2022-26134: Confluence Pre-Auth Remote Code Execution via OGNL Injection☆11Updated 2 years ago
- Burp Suite plugin to copy regex matches from selected requests and/or responses to the clipboard.☆33Updated 2 years ago
- A selection of rebuilt and from scratch exploits, scripts and ideas that can be used in red-teaming scenarios.☆6Updated 10 months ago
- A Burp extension to show the Collaborator client in a tab☆23Updated last year
- This extension provides a way to discover NoSQL injection vulnerabilities.☆23Updated last year
- Simple Python script to sort nuclei scans by severity and URL☆29Updated last year
- The purpose of this repo is to share my research☆14Updated last year
- A fully automated, accurate, and extensive scanner for finding text4shell RCE CVE-2022-42889☆50Updated 2 years ago
- Apache Spark Command Injection PoC Exploit for CVE-2022-33891☆22Updated 2 years ago
- Copy as XMLHttpRequest BurpSuite extension☆30Updated 3 years ago
- Just some random small tools for dealing with asp.net Forms Authentication Cookies☆22Updated 3 years ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆67Updated 2 years ago
- ☆23Updated 5 years ago
- Spring4Shell Burp Scanner☆65Updated 2 years ago