effortlessdevsec / ninjasworkout
Vulnerable NodeJS Web Application
☆93Updated 6 months ago
Alternatives and similar repositories for ninjasworkout:
Users that are interested in ninjasworkout are comparing it to the libraries listed below
- A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration☆78Updated 4 years ago
- Basic Recon For Bug Bounty Hunter - "HuntTheBug" is Basic Scripts For Sub Domain Enumeration> Live Domain Enumeration > Sub Domain Hijack…☆52Updated 3 years ago
- Automated Web Recon Shell Scripts☆51Updated 3 years ago
- XSS Bypass☆28Updated last year
- The scripts I write to help me on my bug bounty hunting☆121Updated 3 years ago
- Advanced Reconnaissance and Web Application Discovery☆79Updated 3 years ago
- Small tool to automate SSRF wordpress and XMLRPC finder☆80Updated 2 years ago
- A burp suite extension that enumerates infrastructure and application admin interfaces (OTG-CONFIG-005)☆118Updated 2 years ago
- This lab is created to demonstrate pass-the-hash, blind sql and SSTI vulnerabilities☆89Updated last year
- HTTP parameter discovery suite.☆61Updated 4 years ago
- R3C0Nizer is the first ever CLI based menu-driven web application B-Tier recon framework.☆151Updated 3 years ago
- To help you go through the pentesting phases and the tools each phase can have. Some pratical examples of the tools are present too.☆46Updated 5 years ago
- Enumerate Subdomains Through Google Dorks☆123Updated 3 years ago
- Learning and hunting SQL injection bugs for 50 continuous days☆75Updated 2 years ago
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆58Updated 3 years ago
- Real world bug bounty wordlists☆112Updated last year
- A replacement of "qsreplace", accepts URLs as standard input, replaces all query string values with user-supplied values and stdout.☆104Updated 2 years ago
- ☆93Updated 3 years ago
- A curated list of different pentesting resources☆29Updated 2 years ago
- A reverse whois tool based on Whoxy API.☆162Updated 10 months ago
- Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.☆145Updated last year
- API Pentesting notes.☆96Updated 3 months ago
- ☆168Updated 2 years ago
- Prototype Pollution Scanner☆109Updated 3 years ago
- Customisable and automated HTTP header injection☆243Updated 7 months ago
- Simple fork from degoogle original project with bug hunting purposes☆88Updated 2 years ago
- ☆154Updated 3 years ago
- Learn how to automate XSS, SSRF, LFI, SQLI, NoSQLi☆40Updated 3 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆130Updated 4 years ago
- golang tool to scan domains or single domains with know security issues against xmlrpc☆60Updated last year