glebarez / padre
Blazing fast, advanced Padding Oracle exploit
☆249Updated 10 months ago
Alternatives and similar repositories for padre:
Users that are interested in padre are comparing it to the libraries listed below
- ☆377Updated last year
- PP-finder Help you find gadget for prototype pollution exploitation☆154Updated 7 months ago
- IIS shortname scanner written in Go☆325Updated 2 years ago
- A lightweight tool for orchestrating and organizing your bug hunting recon / pentesting command-line workflows☆285Updated last year
- TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines fo…☆345Updated 4 months ago
- A fuzzer for finding anomalies and analyzing how servers respond to different HTTP headers☆332Updated last year
- CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request …☆280Updated 7 months ago
- A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.☆503Updated 2 years ago
- ☆150Updated last year
- Session Hijacking Visual Exploitation☆197Updated last year
- Complex payload encoder☆222Updated last year
- Automated learning of regexes for DNS discovery☆364Updated 2 years ago
- gRPC-Web Pentesting Suite + Burp Suite Extension / Hack gRPC-Web Applications☆212Updated last month
- Distribute ordinary bash commands over many systems☆162Updated 2 years ago
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆629Updated last year
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆616Updated 2 weeks ago
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆134Updated 3 months ago
- Enumerate / Dump Docker Registry☆173Updated 11 months ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆258Updated 2 weeks ago
- A rapid HTTP downgrade smuggling scanner written in Go.☆253Updated 10 months ago
- A smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery☆286Updated 4 months ago
- A tool to inspect and attack version 1 GUIDs☆218Updated 2 years ago
- Black box fuzzer for web applications☆426Updated 8 months ago
- A library for detecting known secrets across many web frameworks☆605Updated last week
- Bambdas collection for Burp Suite Professional and Community.☆250Updated 3 weeks ago
- A GraphQL enumeration and extraction tool☆130Updated 2 years ago
- Rust-based high performance domain permutation generator.☆285Updated last year
- Http request smuggling vulnerability scanner☆227Updated 2 years ago
- A streamlined tool for discovering private TLDs for security research.☆180Updated this week
- Local File Inclusion discovery and exploitation tool☆294Updated 3 months ago