A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the system. This code is made for security enthusiasts and professionals only. Use it at your own risk.
☆251Aug 31, 2024Updated last year
Alternatives and similar repositories for Forbidden-Buster
Users that are interested in Forbidden-Buster are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆200Jul 10, 2024Updated 2 years ago
- Mass Assigner is a simple tool made to probe for mass assignment vulnerability through JSON field modification in HTTP requests☆18Jun 22, 2024Updated 2 years ago
- Fuzz 401/403/404 pages for bypasses☆428Jan 22, 2026Updated 6 months ago
- A simple script just made for self use for bypassing 403☆2,182May 30, 2024Updated 2 years ago
- Web Path Finder☆60Nov 22, 2023Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- 🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast…☆1,821Jun 21, 2026Updated last month
- Security testing tool for analyzing HTTP 403 responses and identifying access control misconfigurations in web applications.☆181Jan 6, 2026Updated 6 months ago
- A command-line utility designed to discover subdomains for a given domain in a simple, efficient way. It works by gathering information f…☆120Feb 23, 2026Updated 5 months ago
- NetworkAssessment: Network Compromise Assessment Tool☆95May 31, 2024Updated 2 years ago
- A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash☆53Oct 12, 2024Updated last year
- Tool for analyzing SAP Secure Network Communications (SNC).☆61Apr 16, 2024Updated 2 years ago
- Afuzz is an automated web path fuzzing tool for the Bug Bounty projects.☆311Jul 15, 2023Updated 3 years ago
- 🎯 Chrome Extension - Passive scanner for Dependency Confusion vulnerabilities in npm/PyPI packages☆36Jan 31, 2026Updated 5 months ago
- Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers☆314Mar 31, 2024Updated 2 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- PrestaXSRF is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's critical…☆32Dec 26, 2023Updated 2 years ago
- TrafficWatch, a packet sniffer tool, allows you to monitor and analyze network traffic from PCAP files☆137Jun 1, 2024Updated 2 years ago
- Mass bruteforce authentication of common services with common credentials.☆54Dec 2, 2023Updated 2 years ago
- Go scanner to find web cache poisoning vulnerabilities in a list of URLs☆150Feb 21, 2024Updated 2 years ago
- JoomSploit is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's critical…☆30Dec 19, 2023Updated 2 years ago
- Service that scans your Infrastructure as Code for common vulnerabilities☆49Dec 14, 2023Updated 2 years ago
- Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!☆1,093Mar 24, 2026Updated 4 months ago
- This is the ringzer0 writeup of web exploitation catagery. The name is "Word mean something"☆14Dec 8, 2023Updated 2 years ago
- Unofficial Acunetix CLI tool for automated pentesting and bug hunting across large scopes.☆87Nov 5, 2023Updated 2 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Detects CanaryTokens in Office docs and PDFs (docx, xlsx, pptx, pdf) without triggering alerts☆147Dec 23, 2025Updated 7 months ago
- My Private Bug Hunting Methodology☆442Nov 27, 2024Updated last year
- Reverse shell that can bypass windows defender detection☆176Mar 31, 2026Updated 3 months ago
- 40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...☆1,879Jul 3, 2023Updated 3 years ago
- Tool to parse subdomains from dmarc.live☆154Apr 19, 2024Updated 2 years ago
- A project for fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors☆91Feb 3, 2024Updated 2 years ago
- A fuzzer for finding anomalies and analyzing how servers respond to different HTTP headers☆358Dec 14, 2023Updated 2 years ago
- Chrome extension to extract domains from Google search results - by ofjaaah☆20Dec 24, 2025Updated 7 months ago
- Enumerate valid users within Microsoft Teams and OneDrive with clean output.☆62Feb 4, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- xsschecker tests endpoints for reflected XSS by injecting payloads and checking responses. It prints vulnerable if the payload is reflect…☆38Nov 3, 2025Updated 8 months ago
- ☆75Apr 8, 2024Updated 2 years ago
- NetworkSherlock: powerful and flexible port scanning tool With Shodan☆115Jun 24, 2025Updated last year
- Dig through the Wayback Machine and find sensitive or forgotten files exposed by web servers over time.☆31Mar 27, 2025Updated last year
- RepoReaper is an automated tool crafted to meticulously scan and identify exposed .git repositories within specified domains and their su…☆35Feb 20, 2024Updated 2 years ago
- ♥☆220Sep 7, 2025Updated 10 months ago
- An IIS short filename enumeration tool☆1,206Nov 25, 2024Updated last year