glebarez / padre
Blazing fast, advanced Padding Oracle exploit
☆244Updated 9 months ago
Alternatives and similar repositories for padre:
Users that are interested in padre are comparing it to the libraries listed below
- Complex payload encoder☆219Updated last year
- PP-finder Help you find gadget for prototype pollution exploitation☆151Updated 6 months ago
- ☆149Updated last year
- FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application a…☆156Updated 3 months ago
- A GraphQL enumeration and extraction tool☆130Updated 2 years ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆256Updated 7 months ago
- A lightweight tool for orchestrating and organizing your bug hunting recon / pentesting command-line workflows☆280Updated last year
- IIS shortname scanner written in Go☆323Updated last year
- Distribute ordinary bash commands over many systems☆161Updated 2 years ago
- TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines fo…☆335Updated 2 months ago
- ☆377Updated last year
- ☆115Updated 2 years ago
- Black box fuzzer for web applications☆421Updated 7 months ago
- A smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery☆204Updated 2 months ago
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆585Updated 3 months ago
- Http request smuggling vulnerability scanner☆225Updated 2 years ago
- Find CVE PoCs on GitHub☆143Updated last year
- Enumerate / Dump Docker Registry☆168Updated 10 months ago
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆133Updated 2 months ago
- Rust-based high performance domain permutation generator.☆284Updated last year
- ☆79Updated 7 months ago
- Automated learning of regexes for DNS discovery☆363Updated 2 years ago
- Web dashboard for Interactsh client☆199Updated 2 months ago
- Multi-threaded, IPv6 aware, wordlists/single-user username enumeration via CVE-2018-15473☆105Updated 9 months ago
- Discover new target domains using Content Security Policy☆394Updated this week
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆622Updated last year
- Session Hijacking Visual Exploitation☆194Updated 11 months ago
- Proof of Concept for CVE-2019-18634☆210Updated 3 years ago
- NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.☆371Updated 3 years ago
- CT Log Scanner☆313Updated 3 weeks ago