emadshanab / LFI-Payload-ListLinks
LFI Payloads List coolected from github repos
☆80Updated 5 years ago
Alternatives and similar repositories for LFI-Payload-List
Users that are interested in LFI-Payload-List are comparing it to the libraries listed below
Sorting:
- Wordlist to bruteforce for LFI☆125Updated 5 years ago
- All known and unknown public POC's for wordpress themes and plugins☆78Updated 4 years ago
- A combined wordlists for files and directory discovery☆125Updated 4 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆132Updated 4 years ago
- Prototype Pollution Scanner☆122Updated 4 years ago
- Small tool to automate SSRF wordpress and XMLRPC finder☆81Updated 2 years ago
- Generates target specific word lists for Fuzzing with fuff☆111Updated 4 years ago
- Check AWS S3 instances for read/write/delete access☆121Updated 3 years ago
- 📚 An ultimate collection wordlists of the best-known CMS☆91Updated last year
- This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.☆164Updated 4 years ago
- The scripts I write to help me on my bug bounty hunting☆121Updated 3 years ago
- golang tool to scan domains or single domains with know security issues against xmlrpc☆62Updated last year
- A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration☆79Updated 4 years ago
- ☆96Updated 5 years ago
- ☆10Updated 5 years ago
- Dotmil subdomain discovery tool that scrapes domains from official DoD website directories and certificate transparency logs☆96Updated 4 years ago
- Bug Bounty stuffs, payloads, scripts, profiles, tips and tricks, ...☆149Updated 4 years ago
- A Simple Tool to Pull Paid Bounty Scopes for Wide Recon Actvities☆104Updated 4 years ago
- this tool take a list of subdomains and give you the ip for each☆20Updated 4 years ago
- ☆89Updated 3 years ago
- Burp Bounty profiles compilation, feel free to contribute!☆148Updated 3 years ago
- A collection of code for interacting with API sources directly to improve your understanding of those services.☆65Updated 4 years ago
- Enumerate Subdomains Through Google Dorks (Bypassed Page Filter)☆124Updated 2 weeks ago
- ☆95Updated 3 years ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆120Updated 2 years ago
- Create your Custom Wordlist For Fuzzing☆195Updated 9 months ago
- ☆76Updated last year
- Trickest Workflow for discovering log4j vulnerabilities and gathering the newest community payloads.☆112Updated 3 years ago
- A simple Swagger-ui scanner that can detect old versions vulnerable to various XSS attacks☆59Updated 5 years ago
- Nuclei Templates - Here you will find the templates I use while hunting☆119Updated 3 years ago