johnsaigle / scary-strings
Collection of wordlists containing dangerous function calls in many languages
☆24Updated this week
Alternatives and similar repositories for scary-strings:
Users that are interested in scary-strings are comparing it to the libraries listed below
- A tools for JavaScript Recon☆21Updated 4 years ago
- Extract endpoints from specific Git repository for fuzzing☆22Updated 4 years ago
- A tool for check available dependency packages across npmjs, PyPI or RubyGems registry.☆28Updated 2 years ago
- Tool to extract & validate google fcm server keys from apks☆28Updated 4 years ago
- Return domains in CSP headers in http response☆15Updated 3 years ago
- This extension replaces the default repeater tab name with the URL path of the repeater request.☆22Updated 3 years ago
- View screenshots as a slideshow over http☆15Updated 4 years ago
- A simple tool which makes creating nuclei templates even easier.☆36Updated 7 months ago
- Burp extension to generate multi-step CSRF POC.☆29Updated 5 years ago
- parse ffuf & map endpoints to wordlists☆20Updated 3 years ago
- Security test tool for Blind XSS☆26Updated 4 years ago
- ☆36Updated 4 years ago
- Wrapper around LinkFinder to quickly determine whether endpoints have been added/removed to JavaScript files.☆41Updated 5 years ago
- Burp extension that checks application requests and responses for indicators of vulnerability or targets for attack☆41Updated 2 years ago
- Get URLs from the Wayback Machine. Able to handle large outputs.☆22Updated last year
- ☆9Updated 3 years ago
- gSAST - Grep Static Analysis Security Tool☆10Updated 10 months ago
- Bugbounty utility to store list of enumerated subdomains into an sqlite3 db [one liner style / Pipe and save]☆28Updated 4 years ago
- RegexFinder - Burp Suite extension to passively scan responses for occurrence of regular expression patterns.☆22Updated 3 years ago
- Tool to find stored robots.txt files from the past☆18Updated last year
- XSS scanning with Dalfox on Github-action☆23Updated last year
- A BurpSuite plugin for BBRF☆24Updated 3 months ago
- Automate the process of an S3 bucket subdomain takeover via dangling CNAME record☆25Updated 9 months ago
- Ffuf output browser☆39Updated last year
- Automated compromise detection of the world's most popular packages☆15Updated last year
- commonspeak2 subdomains wordlist generated daily **DEPRECATED** The author(s) of commonspeak2 maintain an official repo with more lists. …☆40Updated 3 years ago
- ☆23Updated 2 years ago
- WebSocket Connection Smuggler☆44Updated 2 years ago
- Atlassian Confluence CVE-2021-26084 one-liner mass checker☆30Updated 3 years ago
- Python script implementing the favicon hash trick to find subdomains.☆28Updated last year