devploit / debugHunter
Discover hidden debugging parameters and uncover web application secrets
☆236Updated last year
Alternatives and similar repositories for debugHunter:
Users that are interested in debugHunter are comparing it to the libraries listed below
- This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.☆239Updated last year
- Use favicon.ico to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.☆201Updated this week
- A lightweight tool for orchestrating and organizing your bug hunting recon / pentesting command-line workflows☆280Updated last year
- Customisable and automated HTTP header injection☆243Updated 7 months ago
- MapperPlus facilitates the extraction of source code from a collection of targets that have publicly exposed .js.map files.☆162Updated 4 months ago
- Made your bugbounty subdomains reconnaissance easier with Hunt3r the web application reconnaissance framework☆164Updated 2 years ago
- Self-hosted passive subdomain continous monitoring tool.☆159Updated last year
- A simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issues☆351Updated last year
- Build your own reconnaissance system with Osmedeus Next Generation☆183Updated 2 weeks ago
- ☆154Updated 3 years ago
- Streamline your recon and vulnerability detection process with SCRIPTKIDDI3, A recon and initial vulnerability detection tool built using…☆149Updated last year
- Hidden parameters discovery suite☆221Updated 2 years ago
- A rapid HTTP downgrade smuggling scanner written in Go.☆253Updated 9 months ago
- A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows, write test cases and track vulnerabiliti…☆113Updated last year
- Opensource assets and vulnerability scanning tool☆162Updated 3 weeks ago
- SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens☆152Updated 2 months ago
- Get related domains / subdomains by looking at Google Analytics IDs☆242Updated 2 years ago
- Local File Inclusion discovery and exploitation tool☆273Updated last month
- Wordlist for web fuzzing, made from a variety of reliable sources including: result from my pentests, git.rip, ChatGPT, Lex, nuclei templ…☆96Updated 2 weeks ago
- Search for sensitive data in Postman public library.☆197Updated last month
- CVE Collection of jQuery UI XSS Payloads☆118Updated 2 years ago
- Custom scan profiles for use with Burp Suite Pro☆121Updated 11 months ago
- ☆165Updated 5 months ago
- A simple tool that helps to find assets/domains based on the Google Analytics ID.☆173Updated last month
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆256Updated 7 months ago
- Automated Tool for Testing Header Based Blind SQL Injection☆271Updated last year
- A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing☆139Updated last year
- Useful "Match and Replace" burpsuite rules☆342Updated last year
- Make URL path combinations using a wordlist☆173Updated last year
- EndExt is a .go tool for extracting all the possible endpoints from the JS files☆188Updated 7 months ago