kleiton0x00 / CORS-one-liner
A one liner Bash command which finds CORS in every possible endpoint.
☆125Updated 4 years ago
Alternatives and similar repositories for CORS-one-liner:
Users that are interested in CORS-one-liner are comparing it to the libraries listed below
- A simple Bash one liner with aim to automate CRLF vulnerability scanning.☆68Updated 4 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆130Updated 3 years ago
- ☆94Updated 3 years ago
- A combined wordlists for files and directory discovery☆120Updated 3 years ago
- ☆124Updated 4 years ago
- Just some public notes that can be useful and i want let the world knows.☆86Updated 4 years ago
- A collection of over 5.1 million sub-domains and assets belonging to public bug bounty programs, compiled into a repo, for performing bul…☆98Updated 3 years ago
- A reverse whois tool based on Whoxy API.☆162Updated 10 months ago
- A tool for append URLs, skipping duplicates/paths & combine parameters.☆120Updated 2 years ago
- Some Tutorials and Things to Do while Hunting That Vulnerability.☆72Updated 4 years ago
- Match and Replace script used to automatically generate JSON option file to BurpSuite☆213Updated 5 years ago
- The project aims at creating target-specific wordlists for any web application that you are testing.☆64Updated 2 years ago
- Burp Extension for easily creating Wordlists☆210Updated 3 years ago
- Wwwordlist is a wordlist generator for pentesters and bug bounty hunters. It extracts words from HTML, URLs, JS/HTTP/input variables, quo…☆101Updated last year
- Get the scope of your bugcrowd programs☆66Updated 4 years ago
- Prototype Pollution Scanner☆109Updated 3 years ago
- List of fresh DNS resolvers updated daily☆109Updated 2 years ago
- A script for installing private Burp Collaborator with free Let's Encrypt SSL-certificate☆205Updated 7 months ago
- All known and unknown public POC's for wordpress themes and plugins☆79Updated 3 years ago
- Secret and/or credential patterns used for gf.☆238Updated 2 years ago
- ☆74Updated 9 months ago
- Dotmil subdomain discovery tool that scrapes domains from official DoD website directories and certificate transparency logs☆96Updated 4 years ago
- Signatures for jaeles scanner by @j3ssie☆116Updated 9 months ago
- Bug Bounty stuffs, payloads, scripts, profiles, tips and tricks, ...☆145Updated 4 years ago
- A script that can resolve an input file of domains and scan them with masscan☆157Updated 4 years ago
- Find subdomains and takeovers.☆84Updated 2 years ago
- ASN reconnaissance script☆124Updated last year
- Simple fork from degoogle original project with bug hunting purposes☆88Updated 2 years ago
- ☆52Updated last year
- 📚 An ultimate collection wordlists of the best-known CMS☆85Updated 8 months ago