chennylmf / OWASP-Web-App-Pentesting-checklists
☆71Updated 4 years ago
Alternatives and similar repositories for OWASP-Web-App-Pentesting-checklists:
Users that are interested in OWASP-Web-App-Pentesting-checklists are comparing it to the libraries listed below
- ☆61Updated 8 months ago
- Sometimes we want to fuzz a set of sub-domain URLs with a common wordlist. Fuzzing them one by one is a tedious task, not to mention the …☆51Updated 3 years ago
- Misc bounty and vulndisc things☆84Updated 4 years ago
- ☆76Updated 4 years ago
- A collection of over 5.1 million sub-domains and assets belonging to public bug bounty programs, compiled into a repo, for performing bul…☆99Updated 3 years ago
- Suite of programs meant to aid in bug hunting and security assessments☆76Updated 5 years ago
- Takeover AWS ips and have a working POC for Subdomain Takeover.☆91Updated 2 months ago
- Recon Custom WordList Ganerator☆58Updated 4 years ago
- Script to test open Akamai ARL vulnerability.☆71Updated 3 years ago
- ☆126Updated 4 years ago
- ☆20Updated last year
- Custom scripts for the PIPER Burp extensions.☆98Updated last year
- Enhanced fork with logging, OpenAPI 3.0 and Python 3 for security monitoring workshops☆42Updated last year
- Generates target specific word lists for Fuzzing with fuff☆110Updated 4 years ago
- BurpSuite extension to inject custom cross-site scripting payloads on every form/request submitted to detect blind XSS vulnerabilities☆111Updated last year
- Generate wordlists for fuzzing API method names☆54Updated 4 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆132Updated 4 years ago
- API Pentesting notes.☆96Updated 5 months ago
- This Repo contains wordlist for subdomain enumeration , php file path, html file path, and js file path☆103Updated 4 years ago
- CollabOzark is a simple tool which helps the researchers track SSRF, RCE, Blind XSS, XXE, External Resource Access payloads triggers.☆137Updated 5 years ago
- BurpSuite Extension: A one-stop pen testing checklist and logger tool☆75Updated 2 years ago
- A collection of code for interacting with API sources directly to improve your understanding of those services.☆65Updated 4 years ago
- Find subdomains and takeovers.☆84Updated 2 years ago
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆58Updated 3 years ago
- Horizontal Domain Discovery☆76Updated last year
- Get the scope of your bugcrowd programs☆67Updated 4 years ago
- This repo includes my analysis of some public reports.☆57Updated 4 years ago
- ☆9Updated 5 years ago
- Searching for virtual hosts among non-resolvable domains☆88Updated 4 years ago
- Cross Origin Resource Sharing MisConfiguration Scanner☆173Updated 3 years ago