This repository contains hit lists to use for web application content discovery.
☆11May 31, 2017Updated 8 years ago
Alternatives and similar repositories for content-discovery-hit-lists
Users that are interested in content-discovery-hit-lists are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This is a Burp extension for adding additional payloads to active scanner that require out-of-band validation. Works great with XSSHunter☆20Feb 16, 2017Updated 9 years ago
- Pack required dlls into a single binary that has no imports and makes direct syscalls on Windows☆28Jul 14, 2017Updated 8 years ago
- "><script>prompt(1)</script>''"><!--<svg>☆18Nov 20, 2015Updated 10 years ago
- PoC's and Slides from 'Gophers, whales and.. clouds? Oh my!' BSides Wellington presentation by Glenn 'devalias' Grant☆17Mar 3, 2018Updated 8 years ago
- Language-agnostic workflow builder. Modular code that goes from dev to prod in a minute with principled design decisions.☆14Mar 11, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A Burp Suite Professional extension for decrypting/decoding various types of cookies.☆12Jun 12, 2019Updated 6 years ago
- Squirtle the Browser-based NTLM Attack Toolkit☆16Apr 13, 2015Updated 11 years ago
- Burp plugin to do random fuzzing of HTTP requests☆33Jan 31, 2017Updated 9 years ago
- A library to facilitate the exploitation of padding oracle attacks☆15Apr 1, 2015Updated 11 years ago
- Burp extension to find and decode BigIP and Netscaler cookies☆15Jul 20, 2018Updated 7 years ago
- Shikata ga nai (仕方がない) encoder ported into go with several improvements☆32Jan 28, 2026Updated 3 months ago
- A curated list of awesome AWS IAM tools, libraries guides, blogs, and other resources☆17Jan 5, 2020Updated 6 years ago
- A tool for fetching archived URLs (to be rewritten in Go).☆40Jul 19, 2018Updated 7 years ago
- A simple bash script that uses smbclient to test access to Windows file shares in automated fashion.☆18Jul 9, 2015Updated 10 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Burp with Friends☆102Jan 21, 2023Updated 3 years ago
- A Burp Suite extension to add a custom header (e.g. JWT)☆20Dec 9, 2021Updated 4 years ago
- A Burp Suite extension that automatically marks similar requests as 'out-of-scope'.☆43May 1, 2020Updated 6 years ago
- Golang IPv6 address enumeration☆357May 27, 2019Updated 6 years ago
- ☆23Feb 18, 2018Updated 8 years ago
- The God Name Server☆36Apr 13, 2026Updated 3 weeks ago
- Some useful test data or payloads☆26Oct 30, 2021Updated 4 years ago
- Image size issues plugin for Burp Suite☆95Jun 27, 2018Updated 7 years ago
- A burp extension to generate sqlmap PoC from target HTTP request.☆27Jan 8, 2017Updated 9 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A pattern for reasonably secure Electron applications☆73Feb 4, 2023Updated 3 years ago
- #️⃣ 🕸️ 👤 HTTP Headers Hashing☆13Aug 27, 2023Updated 2 years ago
- Additional nuclei templates☆38Oct 16, 2023Updated 2 years ago
- baichuan SDK 5.4.x逆向☆10Sep 27, 2020Updated 5 years ago
- syzkaller is an unsupervised coverage-guided kernel fuzzer☆13Oct 3, 2020Updated 5 years ago
- A simple Burp extension for scanning stuffs in CTF☆30Jan 22, 2018Updated 8 years ago
- ☆16Jan 4, 2023Updated 3 years ago
- A Burp Suite extension which performs checks for cross-domain scripting against the DOM, subresource integrity checks, and evaluates Java…☆26Mar 23, 2022Updated 4 years ago
- ☆15May 23, 2019Updated 6 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A parallel scanner that utilises axiom to spin up servers and parallel scan using masscan.☆15Jul 1, 2020Updated 5 years ago
- A Golang API for TheHive☆13Sep 3, 2020Updated 5 years ago
- Burp extension to perform Java Deserialization Attacks☆217Feb 2, 2024Updated 2 years ago
- Python SDK to access the vulnerability database☆22Sep 5, 2019Updated 6 years ago
- An example of obtaining RCE via Redis and CSRF☆76Sep 11, 2016Updated 9 years ago
- A repo of fake committed secrets to test tools that find committed secrets ([dont submit for BB :-) ]☆11Mar 22, 2018Updated 8 years ago
- poc for cve-2017-10661☆12Aug 11, 2017Updated 8 years ago