SpiderLabs / burplay
Burplay is a Burp Extension allowing for replaying any number of requests using same modifications definition. Its main purpose is to aid in searching for Privilege Escalation issues.
☆82Updated 7 years ago
Alternatives and similar repositories for burplay:
Users that are interested in burplay are comparing it to the libraries listed below
- Materials related to the 2017 BSides Las Vegas presentation☆51Updated 4 years ago
- Highlight Burp proxy requests made by different browsers☆30Updated 7 years ago
- WhiteBox CMS analysis☆69Updated last year
- BlindRef serves as the basis for an automated Blind-Based XXE Exploitation Framework☆26Updated 7 years ago
- This is sample code to demonstrate how one can use SQL Injection vulnerability to download local file from server in specific condition. …☆44Updated 7 years ago
- Pillage a git repo found in an accessible web root☆61Updated 13 years ago
- Burp Suite plugin created for using Collaborator tool during manual testing in a comfortable way!☆103Updated 6 years ago
- Tool for checking Whether a domain or its multiple sub-domains are up and running.☆72Updated 6 years ago
- Various tools for managing bug bounty recon and exploration.☆47Updated 2 years ago
- ☆70Updated 7 years ago
- Burp Notes Extension is a plugin for Burp Suite that adds a Notes tab. The tool aims to better organize external files that are created d…☆67Updated 9 months ago
- Penetration Testing Tools Developed by AppSec Consulting.☆48Updated 6 years ago
- Generate MS Word template-based reports with HP WebInspect / Burp Suite Pro input, own custom data and knowledge base.☆66Updated last year
- A Burp Extension to test applications for vulnerability to the Web Cache Deception attack☆136Updated 4 years ago
- A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.☆111Updated 5 years ago
- RFD Checker - security CLI tool to test Reflected File Download issues☆61Updated 6 years ago
- a collection of payloads for common webapps☆73Updated 11 years ago
- A python script that filters, checks the validity, generates clickable link(s) of subdomain(s), and reports their status☆89Updated 4 years ago
- Advanced XPath Injection Tool☆34Updated 9 years ago
- OAuth plugin for Burp Suite Extender☆42Updated 6 years ago
- ActionScript Proof of Concept to perform cross-domain reads☆44Updated 11 years ago
- Dirbuster plugin for Burp Suite☆70Updated 8 years ago
- Subdomain brute force focused on speed and data serialization☆74Updated 2 years ago
- Working Python test and PoC for CVE-2018-11776, includes Docker lab☆125Updated 6 years ago
- Some scripts and exploits☆144Updated 6 years ago
- Disrupt WAF by abusing SSL/TLS Ciphers☆48Updated 6 years ago
- Actarus is a custom tool for bug bounty☆76Updated 5 years ago
- A Python3 based single-file subdomain enumerator☆90Updated 5 years ago
- Burp Suite Extensions☆126Updated 11 years ago
- Verification tools for CVE-2016-1287☆33Updated 7 years ago