hahwul / authz0
🔑 Authz0 is an automated authorization test tool. Unauthorized access can be identified based on URLs and Roles & Credentials.
☆416Updated 4 months ago
Alternatives and similar repositories for authz0:
Users that are interested in authz0 are comparing it to the libraries listed below
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆626Updated last year
- Web dashboard for Interactsh client☆207Updated this week
- Gotator is a tool to generate DNS wordlists through permutations.☆466Updated 2 years ago
- Generate tens of thousands of subdomain combinations in a matter of seconds☆264Updated last year
- Http request smuggling vulnerability scanner☆227Updated 2 years ago
- A fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀☆612Updated 2 years ago
- Discover new target domains using Content Security Policy☆398Updated this week
- ☆518Updated last year
- ☆318Updated 2 months ago
- Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one pl…☆961Updated 2 months ago
- Automated learning of regexes for DNS discovery☆364Updated 2 years ago
- A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.☆503Updated 2 years ago
- Black box fuzzer for web applications☆425Updated 8 months ago
- Vulnerability Scan with Nuclei☆250Updated 4 months ago
- Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!☆861Updated last year
- HTTP Request Smuggling Detection Tool☆491Updated last year
- mx-takeover focuses DNS MX records and detects misconfigured MX records.☆346Updated last year
- hakip2host takes a list of IP addresses via stdin, then does a series of checks to return associated domain names.☆439Updated 2 years ago
- Community curated list of nuclei templates for finding "unknown" security vulnerabilities.☆63Updated 10 months ago
- DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it☆449Updated last year
- Customisable and automated HTTP header injection☆243Updated 9 months ago
- A Security Tool for Enumerating WebSockets☆343Updated 3 years ago
- NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.☆374Updated 3 years ago
- Fast and customizable vulnerability scanner For JIRA written in Python☆317Updated 2 months ago
- Smart context-based SSRF vulnerability scanner.☆349Updated 2 years ago
- Useful "Match and Replace" burpsuite rules☆342Updated last year
- Fleex makes it easy to create multiple VPS on cloud providers and use them to distribute workloads.☆257Updated 7 months ago
- Scrape domain names from SSL certificates of arbitrary hosts☆636Updated 11 months ago
- Prototype pollution scanner using headless chrome☆216Updated 2 years ago
- A tool to check a bunch of URLs that contain reflecting params.☆565Updated 7 months ago