Xss payload for bypassing waf
☆20Apr 18, 2020Updated 6 years ago
Alternatives and similar repositories for noobstuffs
Users that are interested in noobstuffs are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- XSS payloads for bypassing WAF. This repository is updating continuously.☆281Mar 15, 2024Updated 2 years ago
- Nuclei Templates☆25Oct 17, 2024Updated last year
- Describe how to use ffuf different options with examples☆14Jun 13, 2022Updated 4 years ago
- Process URLs and remove duplicate query parameters.☆27Mar 19, 2024Updated 2 years ago
- Cool HackerOne Reports☆23Nov 16, 2022Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A lightweight Python tool to analyze PCAP files and generate network traffic reports. It detects traffic patterns, security concerns, and…☆19Sep 25, 2024Updated 2 years ago
- LogSnare: A playground for testing, preventing, and logging IDOR vulnerabilities.☆35Mar 4, 2024Updated 2 years ago
- A list of notes that I've compiled over time to help with CTF's and the OSCP exam.☆10Dec 29, 2020Updated 5 years ago
- A domain recon tool to help detect DNS based vulnerabilities, such as zone transfers and subdomain takeovers.☆12Mar 25, 2022Updated 4 years ago
- Shared wordlists used for common subdomains , directory bruteforcing etc.☆12Jun 23, 2026Updated 3 months ago
- Cross-Site Scripting (XSS) is one of the most well known web application vulnerabilities. It even has a dedicated chapter in the OWASP To…☆12Jan 30, 2023Updated 3 years ago
- Get 10k subdomains in securitytrails using cookie without apikey.☆43Oct 23, 2025Updated 11 months ago
- Welcome to RFS notes to CRTP - Certified Red Team Professional by Altered Security.☆30Aug 20, 2024Updated 2 years ago
- ☆29Dec 13, 2023Updated 2 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- 判断是不是CDN IP,用于收缩目标资产范围☆10Mar 9, 2022Updated 4 years ago
- Scripts/tools to destroy things☆16Sep 13, 2021Updated 5 years ago
- ☆13Sep 8, 2024Updated 2 years ago
- Passively check for XSS character encodings☆20Mar 9, 2026Updated 6 months ago
- Webarchive is a Go package for pentesters and developers to interacting with the Wayback Machine's CDX API and integrate web archive util…☆11Feb 25, 2024Updated 2 years ago
- A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing☆142Jun 27, 2023Updated 3 years ago
- BurpSiute - BurpBounty Profiles☆20Feb 10, 2023Updated 3 years ago
- this repo contains all nuclei templates for particular vulnerability that i used mosty while hunting..☆13Aug 15, 2024Updated 2 years ago
- Simple Automation script for juniper cve-2023-36845☆19Jan 30, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Extract metadata with SSRF (Server-Side Request Forgery)☆16Jul 23, 2022Updated 4 years ago
- A solid recon tool I use personally.☆30May 12, 2023Updated 3 years ago
- 「🔎」CORS vulnerability scanner☆13Dec 7, 2024Updated last year
- Chameleon Wordlists☆15Sep 13, 2022Updated 4 years ago
- CVE-2023-7028☆58Jan 12, 2024Updated 2 years ago
- A Firefox Web Extension to improve the discovery of DOM XSS.☆293Nov 13, 2024Updated last year
- gh0str3con is a All in one cloud based web Recon tool.☆28Jul 11, 2026Updated 2 months ago
- Ultimate Wordlist for Web Content Discovery☆71Apr 28, 2025Updated last year
- the POC of package.json RCE☆27Jun 24, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆17Jan 31, 2021Updated 5 years ago
- This search engine automates the discovery of sensitive information using customized dorks across GitHub, Google, and Shodan.☆16Oct 16, 2024Updated last year
- ☆47Apr 18, 2023Updated 3 years ago
- Toolset for detecting reflected xss in websites☆16Oct 6, 2018Updated 7 years ago
- Tools and methods that I personally use for Recon and Exploitations☆55May 1, 2025Updated last year
- Example: Client-Side Template Injection with Vue☆25Feb 20, 2023Updated 3 years ago
- All Shell In One. Generate Reverse Shells and/or generate single code that runs all the payloads.☆11Mar 25, 2021Updated 5 years ago