hussein98d / LFI-filesLinks
Wordlist to bruteforce for LFI
☆125Updated 5 years ago
Alternatives and similar repositories for LFI-files
Users that are interested in LFI-files are comparing it to the libraries listed below
Sorting:
- Prototype Pollution Scanner☆126Updated 4 years ago
- LFI Payloads List coolected from github repos☆81Updated 5 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆132Updated 4 years ago
- All known and unknown public POC's for wordpress themes and plugins☆78Updated 4 years ago
- This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.☆164Updated 4 years ago
- ☆95Updated 3 years ago
- Check AWS S3 instances for read/write/delete access☆121Updated 3 years ago
- ☆89Updated 3 years ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆120Updated 2 years ago
- Burp Extension that copies a request and builds a FFUF skeleton☆111Updated last year
- nuclei-bb-templates☆50Updated 3 years ago
- Modified Nuclei Templates Version to FUZZ Host Header☆50Updated 3 years ago
- ☆80Updated 2 years ago
- ☆96Updated 5 years ago
- A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration☆79Updated 4 years ago
- Detects request smuggling via HTTP/2 downgrades.☆93Updated 3 years ago
- A simple Swagger-ui scanner that can detect old versions vulnerable to various XSS attacks☆60Updated 5 years ago
- MNS is a security and reconnaissance tool for monitoring new subdomains☆69Updated 3 weeks ago
- Some contributions in the nuclei-templates repository☆58Updated 3 years ago
- golang tool to scan domains or single domains with know security issues against xmlrpc☆62Updated last year
- Small tool to automate SSRF wordpress and XMLRPC finder☆81Updated 2 years ago
- The scripts I write to help me on my bug bounty hunting☆121Updated 3 years ago
- 4xxbypass☆67Updated 4 years ago
- Trickest Workflow for discovering log4j vulnerabilities and gathering the newest community payloads.☆113Updated 3 years ago
- 📚 An ultimate collection wordlists of the best-known CMS☆91Updated last year
- Extract JavaScript files from burp suite project with ease.☆93Updated 3 years ago
- Directory scans☆83Updated last year
- Dotmil subdomain discovery tool that scrapes domains from official DoD website directories and certificate transparency logs☆96Updated 4 years ago
- A simple tool to detect vulnerabilities described here https://portswigger.net/research/browser-powered-desync-attacks.☆36Updated 2 years ago
- Community curated list of template files for the nuclei engine to find security vulnerability and fingerprinting the targets.☆61Updated last year