ignis-sec / puff
Clientside vulnerability / reflected xss fuzzer
☆149Updated last year
Alternatives and similar repositories for puff:
Users that are interested in puff are comparing it to the libraries listed below
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆130Updated 4 years ago
- Searching for virtual hosts among non-resolvable domains☆87Updated 4 years ago
- This Repo contains wordlist for subdomain enumeration , php file path, html file path, and js file path☆103Updated 4 years ago
- ☆65Updated 2 years ago
- ☆76Updated 4 years ago
- Find subdomains and takeovers.☆84Updated 2 years ago
- ☆61Updated 6 months ago
- A collection of code for interacting with API sources directly to improve your understanding of those services.☆66Updated 4 years ago
- This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.☆163Updated 3 years ago
- A combined wordlists for files and directory discovery☆120Updated 3 years ago
- A simple remote scanner for Atlassian Jira☆120Updated 2 years ago
- Small tool to automate SSRF wordpress and XMLRPC finder☆80Updated 2 years ago
- A reverse whois tool based on Whoxy API.☆162Updated 10 months ago
- A really simple utility to concate wordlists to a domain name - to pipe into your favourite resolver!☆83Updated 4 years ago
- Various Payload wordlists☆235Updated 4 years ago
- The project aims at creating target-specific wordlists for any web application that you are testing.☆64Updated 2 years ago
- Dotmil subdomain discovery tool that scrapes domains from official DoD website directories and certificate transparency logs☆96Updated 4 years ago
- Script to test open Akamai ARL vulnerability.☆70Updated 3 years ago
- Prototype Pollution Scanner☆109Updated 3 years ago
- Burp Extension that copies a request and builds a FFUF skeleton☆110Updated last year
- You can read the writeup on this script here☆193Updated 3 years ago
- ☆48Updated 4 years ago
- List of fresh DNS resolvers updated daily☆109Updated 2 years ago
- A blazing fast & feature rich Amazon S3 bucket enumerator.☆96Updated 2 years ago
- A script for installing private Burp Collaborator with free Let's Encrypt SSL-certificate☆206Updated 7 months ago
- A permutation generation tool written in golang☆210Updated 5 years ago
- HTTP parameter discovery suite.☆94Updated 4 years ago
- jenkinz is a tool to retrieve every build for every job ever created and run on a given Jenkins instance.☆67Updated 5 years ago
- Urls de-duplication tool for better recon.☆139Updated 7 months ago
- CRLF and open redirect fuzzer☆113Updated 3 years ago