WhiteOakSecurity / Dynamic-DTD
A python Flask app that generates dynamic DTDs for easy out-of-band data exfiltration.
☆30Updated 2 years ago
Alternatives and similar repositories for Dynamic-DTD:
Users that are interested in Dynamic-DTD are comparing it to the libraries listed below
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆71Updated 3 years ago
- For unpacking base64:ed "Save items"-content from Burp (From search + proxy history)☆50Updated 2 months ago
- A powerful AWS Cognito analysis and session hijacking toolkit designed for security researchers and penetration testers. CognitoHunter sp…☆20Updated 3 months ago
- ☆56Updated 11 months ago
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆79Updated last year
- ☆52Updated 5 months ago
- Trickest Workflow for discovering log4j vulnerabilities and gathering the newest community payloads.☆110Updated 3 years ago
- A Burp Suite Extension for parsing Project Files from the CLI.☆87Updated 7 months ago
- Improve automated and semi-automated active scanning in Burp Pro☆61Updated 2 years ago
- A simple tool to detect vulnerabilities described here https://portswigger.net/research/browser-powered-desync-attacks.☆36Updated 2 years ago
- A list of "secrets" from JWT sample code and readme files.☆55Updated 4 years ago
- User enumeration and password spraying tool for testing Azure AD☆69Updated 3 years ago
- ☆35Updated 2 years ago
- Use normal web pentest tools to hack Websockets☆18Updated 5 years ago
- A collection of utilities for building extensions using Burp's Montoya API☆50Updated 10 months ago
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆52Updated 7 months ago
- Make better use of the embedded browser that comes by default with Burp☆43Updated last year
- Dump all available paths and/or endpoints on WADL file.☆94Updated this week
- Mine URLs from Browser's Heap Snapshot for fun and profit☆64Updated last year
- A collection of code for interacting with API sources directly to improve your understanding of those services.☆65Updated 4 years ago
- A tool for check available dependency packages across npmjs, PyPI or RubyGems registry.☆28Updated 3 years ago
- BurpSuite Extension: A one-stop pen testing checklist and logger tool☆75Updated 2 years ago
- Declutters URLs in a fast and flexible way, for improving input for web hacking automations such as crawlers and vulnerability scans.☆58Updated 2 years ago
- ☆94Updated 3 years ago
- Some contributions in the nuclei-templates repository☆58Updated 2 years ago
- A simple remote scanner for Atlassian Jira☆121Updated 2 years ago
- ☆62Updated 2 years ago
- BurpSuite extension to convert requests into bcheck scripts☆31Updated last year
- Custom scripts for the PIPER Burp extensions.☆98Updated last year
- ElasticSearch exploit and Pentesting guide for penetration tester☆27Updated 2 years ago