akto-api-security / 30-API-security-testsLinks
🚀 Join us for 30days of daily API security tests. #30days30tests We've spent last 120days building amazing API security tests for the community. Next 30 days we will post test tutorials here.
☆217Updated 2 years ago
Alternatives and similar repositories for 30-API-security-tests
Users that are interested in 30-API-security-tests are comparing it to the libraries listed below
Sorting:
- All About Dependency Confusion Attack, (Detecting, Finding, Mitigating)☆301Updated last year
- Top disclosed reports from HackerOne☆161Updated 4 years ago
- My small collection of reports templates (This is a fork of orignal repo from https://github.com/gwen001/BB-datas)☆127Updated 2 years ago
- Fast and customizable vulnerability scanner For JIRA written in Python☆344Updated 10 months ago
- Never forget where you inject.☆290Updated 2 months ago
- Cyber Security Notes, Methodology, Resources and Tips☆203Updated last week
- Automatic Bug finder with buprsuite☆166Updated 2 years ago
- Useful "Match and Replace" burpsuite rules☆352Updated 2 years ago
- Tips and Tutorials for Bug Bounty and also Penetration Tests.☆123Updated 2 years ago
- ☆249Updated 4 years ago
- User-Agent , X-Forwarded-For and Referer SQLI Fuzzer☆382Updated 2 years ago
- A collection oneliner scripts for bug bounty☆179Updated last year
- This extension will help you to detect GET/POST based XSS vulnerability in any website easily☆243Updated 2 years ago
- This is a python wrapper around the amazing KNOXSS API by Brute Logic☆274Updated last month
- Smart context-based SSRF vulnerability scanner.☆357Updated 3 years ago
- ☆301Updated 2 years ago
- A tool to find good RCE☆169Updated 3 years ago
- i will upload more templates here to share with the comunity.☆560Updated last year
- ☆106Updated 2 years ago
- Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.☆550Updated 8 months ago
- EndExt is a .go tool for extracting all the possible endpoints from the JS files☆216Updated last year
- A hacking tool for bug bounties. Sharing and modifying is encouraged!☆244Updated 2 years ago
- Arsenal is a Simple shell script (Bash) used to install tools and requirements for Bug Bounty☆280Updated last year
- A list of edge cases that occur in bug bounty programs, conversations on how they should be handled. The goal is to standardise the way t…☆235Updated 3 years ago
- MapperPlus facilitates the extraction of source code from a collection of targets that have publicly exposed .js.map files.☆285Updated last year
- Detailed information about API key / OAuth token (Description, Request, Response, Regex, Example)☆285Updated 2 years ago
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆685Updated last year
- 40,000+ Nuclei templates for security scanning and detection across diverse web applications and services☆335Updated last year
- Automated tool for domains & subdomains gathering☆189Updated 2 years ago
- A comprehensive list of custom filters for Logger++ to identify various vulnerabilities in different API styles☆228Updated last year