A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the system. This code is made for security enthusiasts and professionals only. Use it at your own risk.
☆251Aug 31, 2024Updated last year
Alternatives and similar repositories for Forbidden-Buster
Users that are interested in Forbidden-Buster are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆201Jul 10, 2024Updated 2 years ago
- Mass Assigner is a simple tool made to probe for mass assignment vulnerability through JSON field modification in HTTP requests☆18Jun 22, 2024Updated 2 years ago
- Fuzz 401/403/404 pages for bypasses☆431Jan 22, 2026Updated 6 months ago
- A simple script just made for self use for bypassing 403☆2,183May 30, 2024Updated 2 years ago
- Web Path Finder☆60Nov 22, 2023Updated 2 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- 🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast…☆1,830Jun 21, 2026Updated last month
- Security testing tool for analyzing HTTP 403 responses and identifying access control misconfigurations in web applications.☆184Jan 6, 2026Updated 7 months ago
- A command-line utility designed to discover subdomains for a given domain in a simple, efficient way. It works by gathering information f…☆120Feb 23, 2026Updated 5 months ago
- NetworkAssessment: Network Compromise Assessment Tool☆95May 31, 2024Updated 2 years ago
- A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash☆53Oct 12, 2024Updated last year
- Tool for analyzing SAP Secure Network Communications (SNC).☆61Apr 16, 2024Updated 2 years ago
- Afuzz is an automated web path fuzzing tool for the Bug Bounty projects.☆310Jul 15, 2023Updated 3 years ago
- 🎯 Chrome Extension - Passive scanner for Dependency Confusion vulnerabilities in npm/PyPI packages☆37Jan 31, 2026Updated 6 months ago
- Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers☆312Mar 31, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- PrestaXSRF is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's critical…☆34Dec 26, 2023Updated 2 years ago
- TrafficWatch, a packet sniffer tool, allows you to monitor and analyze network traffic from PCAP files☆137Jun 1, 2024Updated 2 years ago
- Mass bruteforce authentication of common services with common credentials.☆55Dec 2, 2023Updated 2 years ago
- Go scanner to find web cache poisoning vulnerabilities in a list of URLs☆150Feb 21, 2024Updated 2 years ago
- JoomSploit is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's critical…☆31Dec 19, 2023Updated 2 years ago
- Service that scans your Infrastructure as Code for common vulnerabilities☆49Dec 14, 2023Updated 2 years ago
- Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!☆1,100Aug 5, 2026Updated last week
- Unofficial Acunetix CLI tool for automated pentesting and bug hunting across large scopes.☆87Nov 5, 2023Updated 2 years ago
- This is the ringzer0 writeup of web exploitation catagery. The name is "Word mean something"☆14Dec 8, 2023Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Detects CanaryTokens in Office docs and PDFs (docx, xlsx, pptx, pdf) without triggering alerts☆149Updated this week
- My Private Bug Hunting Methodology☆447Nov 27, 2024Updated last year
- Reverse shell that can bypass windows defender detection☆177Mar 31, 2026Updated 4 months ago
- 40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...☆1,883Jul 3, 2023Updated 3 years ago
- Tool to parse subdomains from dmarc.live☆154Apr 19, 2024Updated 2 years ago
- A project for fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors☆91Feb 3, 2024Updated 2 years ago
- A fuzzer for finding anomalies and analyzing how servers respond to different HTTP headers☆359Dec 14, 2023Updated 2 years ago
- Chrome extension to extract domains from Google search results - by ofjaaah☆20Dec 24, 2025Updated 7 months ago
- Enumerate valid users within Microsoft Teams and OneDrive with clean output.☆62Feb 4, 2025Updated last year
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- xsschecker tests endpoints for reflected XSS by injecting payloads and checking responses. It prints vulnerable if the payload is reflect…☆38Nov 3, 2025Updated 9 months ago
- ☆75Apr 8, 2024Updated 2 years ago
- Dig through the Wayback Machine and find sensitive or forgotten files exposed by web servers over time.☆31Mar 27, 2025Updated last year
- NetworkSherlock: powerful and flexible port scanning tool With Shodan☆115Jun 24, 2025Updated last year
- RepoReaper is an automated tool crafted to meticulously scan and identify exposed .git repositories within specified domains and their su…☆35Feb 20, 2024Updated 2 years ago
- ♥☆220Sep 7, 2025Updated 11 months ago
- An IIS short filename enumeration tool☆1,214Nov 25, 2024Updated last year