lauritzh / domscan
Simple tool to scan a website for (DOM-based) XSS vulnerabilities and Open Redirects.
☆231Updated this week
Alternatives and similar repositories for domscan:
Users that are interested in domscan are comparing it to the libraries listed below
- User-Agent , X-Forwarded-For and Referer SQLI Fuzzer☆381Updated last year
- Automated Tool for Testing Header Based Blind SQL Injection☆266Updated last year
- De-clutter a list of URLs☆312Updated last month
- EndExt is a .go tool for extracting all the possible endpoints from the JS files☆187Updated 6 months ago
- This is a python wrapper around the amazing KNOXSS API by Brute Logic☆236Updated this week
- A lightweight tool for orchestrating and organizing your bug hunting recon / pentesting command-line workflows☆277Updated last year
- LEAKEY is a bash script which checks and validates for leaked credentials. The idea behind LEAKEY is to make it highly customizable and e…☆345Updated last year
- An Automated Subdomain Enumeration Tool☆248Updated 3 months ago
- My Priv8 Nuclei Templates☆296Updated 8 months ago
- Local File Inclusion discovery and exploitation tool☆261Updated 2 weeks ago
- Never forget where you inject.☆227Updated 2 years ago
- ☆237Updated 3 years ago
- Crtsh Subdomain Enumeration | This bash script makes it easy to quickly save and parse the output from https://crt.sh website.☆204Updated 4 months ago
- SubDominator helps you discover subdomains associated with a target domain efficiently and with minimal impact for your Bug Bounty☆492Updated 3 weeks ago
- A tool to find good RCE☆170Updated 2 years ago
- A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidde…☆333Updated last month
- i will upload more templates here to share with the comunity.☆538Updated 9 months ago
- ☆192Updated 2 years ago
- jsleak is a tool to find secret , paths or links in the source code during the recon.☆491Updated 3 months ago
- ☆161Updated 2 months ago
- Self-hosted passive subdomain continous monitoring tool.☆159Updated 11 months ago
- Arsenal is a Simple shell script (Bash) used to install tools and requirements for Bug Bounty☆272Updated 7 months ago
- Finding XSS during recon☆254Updated 2 years ago
- A tool to quickly do keyword searches over Gitlab and Github for OSINT & bug bounty recon☆231Updated last year
- ☆130Updated 7 months ago
- A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas i…☆169Updated 4 months ago
- A fuzzer for finding anomalies and analyzing how servers respond to different HTTP headers☆330Updated last year
- Subprober is a powerful and efficient subdomain scanning tool written in Python. With the ability to handle large lists of subdomains. Th…☆230Updated last week
- Find subdomains with GPT, for free☆337Updated 8 months ago
- Useful "Match and Replace" burpsuite rules☆340Updated last year