Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.
☆61Jul 12, 2026Updated 2 months ago
Alternatives and similar repositories for Authz-ExeC
Users that are interested in Authz-ExeC are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0☆21Jul 20, 2026Updated 2 months ago
- rep+ — Burp-style HTTP Repeater for Firefox DevTools with built-in AI to explain requests and suggest attacks☆37Jan 8, 2026Updated 8 months ago
- My Main App Hacking CheckList☆35Jun 20, 2026Updated 3 months ago
- Fast Go-based XSS assessment toolkit☆20Mar 18, 2026Updated 6 months ago
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆24Mar 16, 2026Updated 6 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- IDOR Scanner is a Burp Suite extension that automates the detection and enumeration of potentially vulnerable numeric fields to identify …☆45Feb 24, 2025Updated last year
- ☆50Feb 27, 2026Updated 7 months ago
- TokenTwin Checker — Dual Token BAC/IDOR Tester for Burp Suite☆97Aug 24, 2026Updated last month
- 0xJS is an AI-powered JavaScript Security Tool☆67Apr 16, 2026Updated 5 months ago
- ☆13Mar 6, 2025Updated last year
- ☆16Apr 17, 2025Updated last year
- CVE-2025-55182-bypass-waf☆31Jan 8, 2026Updated 8 months ago
- Apkx-Hunter is an Android Static Analysis Framework in Debian Package written entirely in C with OWASP MASVS scanning with 15 categories …☆94Sep 15, 2026Updated 2 weeks ago
- ☆89May 26, 2026Updated 4 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Advanced JWT decoding & cracking toolkit with a user-friendly UI for security testing☆52Jul 10, 2026Updated 2 months ago
- A Burp Suite extension that converts IP addresses to decimal notation, useful for SSRF bypass and WAF evasion testing. Created by Harshad…☆13Dec 9, 2024Updated last year
- Here's an updated Google Dorking list for 2025 Bug Bounty Hunting, incorporating new patterns and, the latest trends.☆21Apr 26, 2025Updated last year
- Stealth hybrid URL mapper☆31May 1, 2026Updated 5 months ago
- 蜜罐检测工具,支持自动化URL去重、多线程控制及智能速率限制。可识别伪装服务。☆15Jun 5, 2025Updated last year
- Welcome to the 403 and 401 Bypass Techniques and Bug Bounty Tips repository! This repo is a collection of methods and strategies to bypas…☆38Dec 26, 2024Updated last year
- Fetch, download, and decompile Android/iOS/Exe assets from HackerOne bug bounty programs☆43Jun 24, 2026Updated 3 months ago
- all round pentest skill☆442Sep 16, 2026Updated 2 weeks ago
- Passive JavaScript reconnaissance for penetration testers — bridging Burp Suite traffic into structured, AST-based analysis in VSCode.☆36Feb 5, 2026Updated 7 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- ☆10Oct 30, 2019Updated 6 years ago
- ☆70Jul 12, 2026Updated 2 months ago
- A bug bounty tool for bypassing 401/403 access restrictions and testing endpoint accessibility.☆54Updated this week
- A simple browser extension to quickly find interesting security-related information on a webpage.☆190Sep 25, 2026Updated last week
- This lab is for **EDUCATIONAL PURPOSES ONLY**. Use it responsibly and only on systems you own or have explicit permission to test. Do not…☆24Feb 20, 2026Updated 7 months ago
- A Fuzzing skill based on purely what i know.☆43Jun 3, 2026Updated 4 months ago
- Blind XSS SVG☆10Mar 27, 2023Updated 3 years ago
- Burp extension to track your current IP address. Extension focused for red teams where the attacker needs to log all used IP addresses.☆26Nov 2, 2025Updated 11 months ago
- Auto exploitation tool for CVE-2024-24401.☆35Sep 7, 2024Updated 2 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Advanced test for proxy & waf☆13Feb 10, 2026Updated 7 months ago
- A scanner of the "World's Scariest" scanner☆17Dec 7, 2022Updated 3 years ago
- CVE-2025-3248 Langflow RCE Exploit☆17Jun 17, 2025Updated last year
- Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, …☆184May 12, 2026Updated 4 months ago
- 🎯 Chrome Extension - Passive scanner for Dependency Confusion vulnerabilities in npm/PyPI packages☆43Jan 31, 2026Updated 8 months ago
- Learning JAVA for Security☆33Jun 9, 2022Updated 4 years ago
- BackupFinder discovers backup files on web servers by generating intelligent patterns.☆111Jul 29, 2025Updated last year