harisec / orange-confusion-attacks
Repro for Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!
☆20Updated 8 months ago
Alternatives and similar repositories for orange-confusion-attacks:
Users that are interested in orange-confusion-attacks are comparing it to the libraries listed below
- This tool automates the process of running FFUF (Fuzz Faster U Fool) and post-processing its results to extract valid URLs. It supports b…☆34Updated 5 months ago
- Ffuf output browser☆39Updated 2 years ago
- Web cache poisoning vulnerability scanner.☆66Updated 2 years ago
- JSNotify is a Python script designed to monitor JavaScript files in a specified directory for changes. This tool can be used by developer…☆18Updated last year
- Looks for parameters in urls☆34Updated 6 months ago
- Advanced test for proxy & waf☆13Updated 7 months ago
- Tool to fuzz for interesting vhost.☆23Updated 3 months ago
- A Go tool that gets the newest PRs from projectdiscovery/nuclei-templates.☆54Updated last year
- Custom nuclei templates for bug hunting.....☆25Updated 10 months ago
- Results from analyzing data gathered from 1.6 billion subdomains☆26Updated 6 months ago
- vīlicus is a bug bounty api dashboard☆40Updated last year
- A simple utility to generate domain names with all possible TLDs☆23Updated 2 years ago
- A Burp Extension that makes it easier to view all script code on a Response.☆16Updated last year
- Enhanced 403 bypass header☆21Updated 2 years ago
- Get list of subsidiaries for a selected company☆28Updated 4 months ago
- This repository has workflows created for https://github.com/RikunjSindhwad/Task-Ninja☆24Updated 8 months ago
- ☆33Updated last week
- Bcheck scripts for Burp☆28Updated 8 months ago
- Make better use of the embedded browser that comes by default with Burp☆43Updated last year
- Gouge is a simple Burp extension to extract or gouge all URLs which are seen in JS files as you visit different websites/webpages in Burp…☆28Updated 9 months ago
- Help recon of hostnames from specific ASN or CIDR, thanks to Robtex and BGP.HE☆53Updated 6 months ago
- A powerful AWS Cognito analysis and session hijacking toolkit designed for security researchers and penetration testers. CognitoHunter sp…☆20Updated 3 months ago
- Simple bash Script to automate initial recon using (httpx, puredns, regulator, wayback, katana, aquatone)☆34Updated 3 weeks ago
- Find CVEs that don't have a Detectify modules.☆21Updated 2 years ago
- ☆15Updated last year
- Burp extension used to snip any header from all the requests.☆22Updated last year
- ☆17Updated last year
- tool that generates bypasses for open redirects☆52Updated 3 years ago
- ☆18Updated 10 months ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆71Updated 3 years ago