SecWiki / SecListsLinks
SecLists is the security tester's companion. It is a collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strings, fuzzing payloads, and many more.
☆13Updated 9 years ago
Alternatives and similar repositories for SecLists
Users that are interested in SecLists are comparing it to the libraries listed below
Sorting:
- This is a webshell open source project☆29Updated 9 years ago
- Curated list of public penetration testing reports released by several consulting firms☆12Updated 8 years ago
- Struts2 S2-045-Nmap NSE script☆50Updated 8 years ago
- A BurpSuite plugin to detect Same Origin Method Execution vulnerabilities☆60Updated 8 years ago
- check cmd execute☆13Updated 8 years ago
- CVE-2017-9791☆27Updated 7 years ago
- 投诉太狠啊,换个地方自己下吧☆14Updated 9 years ago
- ppsx file generator for cve-2017-8570 (based on bhdresh/cve-2017-8570)☆67Updated 7 years ago
- Simple script to automate brutforcing blind sql injection vulnerabilities☆51Updated 7 years ago
- Java Untrusted Deserialization Exploits Tools☆67Updated 9 years ago
- Threat Research Blog 威胁情报提取与溯源技术研究小组☆29Updated 7 years ago
- Burp extension to help developers replicate findings from pen tests☆70Updated 10 months ago
- Automated information gathering tool for pentest☆54Updated 8 years ago
- A collection of tools found on Github☆26Updated 9 years ago
- Burp Suite plugin which implement PyJFuzz for fuzzing web application.☆56Updated 8 years ago
- CVE-2017-7269 to webshell or shellcode loader☆87Updated 8 years ago
- ☆46Updated 9 years ago
- A cms discover recognize tool in python☆19Updated 9 years ago
- ☆9Updated 7 years ago
- scripts used in my pentest work.☆44Updated 9 years ago
- a poc framework to test hosts via zoomeye sdk☆32Updated 7 years ago
- New On Live Web Vul Scan☆41Updated 9 years ago
- Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)☆127Updated 2 years ago
- Flash XSS Scanner☆54Updated 8 years ago
- Proof of concept showing how java byte code can be injected through InitialContext.lookup() calls☆42Updated 9 years ago
- ☆79Updated 10 years ago
- CVE-2016-8610 (SSL Death Alert) PoC☆34Updated 8 years ago
- CVE-2017-10271 WEBLOGIC RCE (TESTED)☆39Updated 7 years ago
- A Java serializer in JavaScript☆81Updated 7 years ago
- ☆4Updated 2 years ago