Sivnerof / Sources-And-Sinks-Cheatsheet
A cheatsheet for common JavaScript sources and sinks that lead to potential vulnerabilities.
☆32Updated last year
Alternatives and similar repositories for Sources-And-Sinks-Cheatsheet
Users that are interested in Sources-And-Sinks-Cheatsheet are comparing it to the libraries listed below
Sorting:
- Chrome extension for automating CSPT discovery☆83Updated 3 weeks ago
- CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.☆139Updated 10 months ago
- ☆154Updated 2 years ago
- Go scanner to find web cache poisoning vulnerabilities in a list of URLs☆138Updated last year
- JSSCM detects expired domains for Stored XSS exploitation during browsing.☆46Updated last month
- A chrome/Firefox extension to retrieve and load react javascript chunks all at once for a wide range of javascript techs☆67Updated 2 months ago
- This repository stores some of my custom BCheck Scan configurations. Its goal is to identify intriguing elements that warrant further man…☆96Updated last year
- ☆126Updated 3 years ago
- unleashed ffuf☆112Updated 10 months ago
- Finds graphql queries in javascript files☆61Updated 11 months ago
- Find subdomains on GitLab.☆98Updated last year
- ☆31Updated last year
- Golang tool which helps dropping the irrelevant entries from your ffuf result file.☆136Updated 8 months ago
- ☆95Updated 3 years ago
- ParamScan is a chrome extension for finding reflected parameters in a webpage.☆81Updated 4 months ago
- This Tool To Test Machine Keys In View State☆69Updated 7 months ago
- ☆132Updated 6 months ago
- A powerful JavaScript monitoring tool for bug bounty hunters. Track changes in JavaScript files across websites, detect new attack surfac…☆75Updated 3 weeks ago
- ☆78Updated 2 years ago
- BChecks collection for Burp Suite Professional☆98Updated 11 months ago
- GQLSpection - parses GraphQL introspection schema and generates possible queries☆84Updated 2 months ago
- A fast, minimalistic scanner for time-based SQL injection (SQLi) detection – built in Go.☆66Updated last week
- This repository updates latest Bug Bounty medium writeups every 10 minutes, https://readmedium.com/Medium_URL, https://archive.ph/Medium_…☆70Updated this week
- This repo contains different variants of Bug Bounty & Security & Pentest & Tech related Articles☆44Updated 4 months ago
- A tool for monitoring bug bounty programs across multiple platforms to track scope changes.☆25Updated this week
- A powerful bash script for massive XSS scanning leveraging Brute Logic's KNOXSS API☆71Updated 3 months ago
- A path-normalization pentesting tool.☆127Updated last year
- Community curated list of nuclei templates for finding "unknown" security vulnerabilities.☆36Updated 10 months ago
- ☆65Updated 8 months ago
- A replacement of "qsreplace", accepts URLs as standard input, replaces all query string values with user-supplied values and stdout.☆105Updated 3 years ago