aress31 / flarequench
Burp Suite plugin that adds additional checks to the passive scanner to reveal the origin IP(s) of Cloudflare-protected web applications.
☆61Updated last year
Related projects ⓘ
Alternatives and complementary repositories for flarequench
- Burp extension that checks application requests and responses for indicators of vulnerability or targets for attack☆41Updated last year
- web-based-fuzzer☆32Updated 4 years ago
- BurpSuite's payload-generation extension aiming at applying fuzzed test-cases depending on the type of payload (integer, string, path; JS…☆39Updated 3 years ago
- Google Chrome Extension automates testing fundamental Web Problems via Chrome☆21Updated 3 years ago
- Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities☆41Updated last year
- Broken Link Hijacking Burp Extension☆55Updated 5 years ago
- Clickjacking PoC Generator☆35Updated 4 years ago
- Virtual host wordlist☆51Updated 3 years ago
- This is the Go Server that relays all HTTP requests and responses between clients.☆27Updated last year
- RAS(RAndom Subdomain) Fuzzer☆43Updated 4 years ago
- Wrapper around LinkFinder to quickly determine whether endpoints have been added/removed to JavaScript files.☆40Updated 4 years ago
- Literally spray blind xss payloads everywhere.☆25Updated 2 years ago
- Image Tragick Exploit Tool Using Burp Collaborator☆35Updated 6 months ago
- This burpsuite extender provides a solution on testing Enterprise applications that involve security Authorization tokens into every HTTP…☆46Updated 5 years ago
- JavaScript functions intended to be used as an XSS payload against a WordPress admin account.☆53Updated 4 years ago
- ☆31Updated 5 years ago
- Python script to give you subsets of the nmap "top-ports". For example, I want the 10th to 100th most common TCP ports. Spits out a comma…☆17Updated 4 years ago
- Hacked together script for feeding urls into Burp's Sitemap☆92Updated 2 years ago
- A command-line tool for Cross-Site WebSocket Hijacking☆39Updated last year
- Get all possible href | src | url from target url or domain☆41Updated 4 years ago
- A python library to automate time-based blind SQL injection☆49Updated 5 years ago
- ☆28Updated 4 years ago
- Deploy a Private Burpsuite Collaborator using boto3 Python Library☆57Updated 4 years ago
- Extract subdomains from rapiddns.io☆23Updated 2 years ago
- CVE-2020-9484 Mass Scanner, Scan a list of urls for Apache Tomcat deserialization (CVE-2020-9484) which could lead to RCE☆32Updated 4 years ago
- unicode abnormalizer to takes a unicode string and abnormalizes it by character replacment☆27Updated 4 years ago
- ☆22Updated 2 years ago
- Finds Directory Listings or open S3 buckets from a list of URLs☆50Updated 2 years ago