gnothiseautonlw / burp-shell-fwd-lfiLinks
A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration
☆79Updated 4 years ago
Alternatives and similar repositories for burp-shell-fwd-lfi
Users that are interested in burp-shell-fwd-lfi are comparing it to the libraries listed below
Sorting:
- Small tool to automate SSRF wordpress and XMLRPC finder☆81Updated 2 years ago
- Prototype Pollution Scanner☆121Updated 4 years ago
- ☆54Updated 4 years ago
- Wordlist to bruteforce for LFI☆124Updated 5 years ago
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆59Updated 3 years ago
- All known and unknown public POC's for wordpress themes and plugins☆78Updated 4 years ago
- 📚 An ultimate collection wordlists of the best-known CMS☆91Updated last year
- ☆32Updated 2 years ago
- Simple fork from degoogle original project with bug hunting purposes☆89Updated 3 years ago
- The project aims at creating target-specific wordlists for any web application that you are testing.☆66Updated 3 years ago
- Check AWS S3 instances for read/write/delete access☆121Updated 3 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆132Updated 4 years ago
- The scripts I write to help me on my bug bounty hunting☆121Updated 3 years ago
- Automated Web Recon Shell Scripts☆51Updated 3 years ago
- ☆157Updated 3 years ago
- ☆89Updated 3 years ago
- LFI Payloads List coolected from github repos☆80Updated 5 years ago
- a burp extension for dynamic payload generation to detect injection flaws (RCE, LFI, SQLi), creates access matrix based user sessions to …☆49Updated 3 years ago
- ☆81Updated 2 years ago
- golang tool to scan domains or single domains with know security issues against xmlrpc☆62Updated last year
- The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489☆31Updated last year
- Script for Bug Bounty☆29Updated 3 years ago
- Bug Bounty & Other Stuff☆57Updated 3 years ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆120Updated 2 years ago
- ☆42Updated 4 years ago
- A replacement of "qsreplace", accepts URLs as standard input, replaces all query string values with user-supplied values and stdout.☆108Updated 3 years ago
- Trickest Workflow for discovering log4j vulnerabilities and gathering the newest community payloads.☆111Updated 3 years ago
- AWS S3 open bucket poc automated script.☆57Updated 3 years ago
- Extract JavaScript files from burp suite project with ease.☆90Updated 3 years ago
- A Simple Tool to Pull Paid Bounty Scopes for Wide Recon Actvities☆104Updated 4 years ago