chenjj / Awesome-HTTPRequestSmuggling
A curated list of awesome blogs and tools about HTTP request smuggling attacks. Feel free to contribute! š»
ā124Updated 2 years ago
Alternatives and similar repositories for Awesome-HTTPRequestSmuggling:
Users that are interested in Awesome-HTTPRequestSmuggling are comparing it to the libraries listed below
- Detects request smuggling via HTTP/2 downgrades.ā92Updated 2 years ago
- WordPress Plugin Update Confusionā67Updated 3 years ago
- This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.ā162Updated 3 years ago
- Hidden parameters discovery suiteā221Updated 2 years ago
- CRLF and open redirect fuzzerā112Updated 3 years ago
- Pass list of urls with FUZZ in and it will check if it has found a potential SSRF.ā106Updated 2 years ago
- Burpsuite plugin for Interact.shā202Updated 7 months ago
- A XSS mind map ;)ā56Updated 9 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or Lā¦ā130Updated 3 years ago
- Workshop given at Hack in Paris 2019ā121Updated last year
- All known and unknown public POC's for wordpress themes and pluginsā79Updated 3 years ago
- Match and Replace script used to automatically generate JSON option file to BurpSuiteā213Updated 5 years ago
- ā91Updated 4 years ago
- Bug Bounty stuffs, payloads, scripts, profiles, tips and tricks, ...ā145Updated 4 years ago
- Toolkit to detect and keep track on Blind XSS, XXE & SSRFā296Updated 5 years ago
- Burp Suite Extension useful to verify OAUTHv2 and OpenID securityā169Updated 3 months ago
- Client-Side Prototype Pollution Toolsā84Updated 3 years ago
- Collection of quirky behaviours of code and the CTF challenges that I made around them.ā27Updated 4 years ago
- Wordlist to bruteforce for LFIā119Updated 5 years ago
- Enumerate Subdomains Through Google Dorksā123Updated 3 years ago
- bug bounty disclosed reportsā111Updated 3 years ago
- Nuclei templates written by us.ā266Updated 3 years ago
- ā94Updated 3 years ago
- a Go code to detect leaks in JS files via regex patternsā140Updated 3 years ago
- ā285Updated 2 years ago
- A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.ā177Updated 3 years ago
- Smart ssrf scanner using different methods like parameter brute forcing in post and get...ā276Updated 3 years ago
- A Burp Suite extension to extract datas from source code while browsing.ā153Updated 10 months ago
- Unofficial documentation for the great tool Param Minerā176Updated 2 years ago
- ā165Updated 2 years ago