humblelad / Awesome-XSS-Payloads
Exotic and uncommon XSS Vectors to hit the target as quickly as possible.
☆18Updated 4 years ago
Alternatives and similar repositories for Awesome-XSS-Payloads:
Users that are interested in Awesome-XSS-Payloads are comparing it to the libraries listed below
- A companion repo to accompany detailed guides and YouTube content to allow users to follow along☆13Updated 4 years ago
- Get URLs from the Wayback Machine. Able to handle large outputs.☆22Updated last year
- Information-Gathering Shell Script☆30Updated 4 years ago
- Host Header Injection Scanner☆44Updated 4 years ago
- Extract endpoints from specific Git repository for fuzzing☆23Updated 4 years ago
- Collection of content discovery wordlists in one wordlist.☆38Updated 3 years ago
- Validate proxies for specific domain☆36Updated 3 years ago
- Passive subdomain enumeration tool with http-probe.☆33Updated 4 years ago
- A set of tools, procedures, and playbooks for performing bug bounties☆15Updated 6 years ago
- King of Bug Bounty Tips Simple Tool☆13Updated 3 years ago
- Easy discovery of assets☆13Updated 2 years ago
- Burp extension to increment a parameter in each active scan request☆12Updated 4 years ago
- Simple API for storing all incoming XSS requests and various XSS templates.☆45Updated 9 months ago
- CRLFMap is a tool to find HTTP Splitting vulnerabilities☆25Updated 4 years ago
- A tool for check available dependency packages across npmjs, PyPI or RubyGems registry.☆28Updated 3 years ago
- Bugbounty utility to store list of enumerated subdomains into an sqlite3 db [one liner style / Pipe and save]☆27Updated 4 years ago
- Application for logging HTTP and DNS Requests☆14Updated 3 years ago
- a vulnerable GraphQL application☆19Updated 5 years ago
- This script scrapes the list of open Bug Bounty Programs from openbugbounty.org☆27Updated 3 years ago
- Reconnaisance Tool☆11Updated 4 years ago
- ☆21Updated 4 years ago
- Extract endpoints marked as disallow in robots files to generate wordlists.☆57Updated 3 years ago
- Various scripts & tools☆12Updated last year
- Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of …☆13Updated last year
- Ffuf output browser☆39Updated 2 years ago
- WebSocket Connection Smuggler☆45Updated 2 years ago
- The objective of this Burp Suite extension is the flexible and dynamic extraction, correlation, and structured presentation of informatio…☆56Updated 2 years ago
- Burp Suite extension for extracting metadata from files☆20Updated 4 years ago
- Another Subdomain ENumeration Tool☆11Updated 2 years ago
- Checks whether a domain is hosted on a cloud service such as AWS, Azure or CloudFlare☆59Updated 2 years ago