Correlated injection proxy tool for XSS Hunter
☆259Dec 26, 2022Updated 3 years ago
Alternatives and similar repositories for xsshunter_client
Users that are interested in xsshunter_client are comparing it to the libraries listed below
Sorting:
- The XSS Hunter service - a portable version of XSSHunter.com☆1,542Dec 7, 2022Updated 3 years ago
- XSS Hunter correlated injection API guide☆21Mar 24, 2016Updated 9 years ago
- An automated XSS payload generator written in python.☆314Jun 2, 2016Updated 9 years ago
- A simple bash script that uses smbclient to test access to Windows file shares in automated fashion.☆19Jul 9, 2015Updated 10 years ago
- A collection of scripts that run on my web server. Mainly for debugging SSRF, blind XSS, and XXE vulnerabilities.☆549Jun 12, 2017Updated 8 years ago
- This tool can be used to brute discover GET and POST parameters☆1,394Aug 24, 2019Updated 6 years ago
- ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.☆2,244Jan 8, 2026Updated last month
- ☆332Jan 8, 2018Updated 8 years ago
- XSS Hunter Burp Plugin☆151Aug 31, 2018Updated 7 years ago
- Distributed password cracker for operating over high latency networks of loosely coupled hosts.☆13Jul 30, 2013Updated 12 years ago
- Nameserver DNS poisoning attacks made easy☆526Feb 26, 2017Updated 9 years ago
- A very simple bridge for performing Flash HTTP requests with JavaScript☆81Jul 21, 2015Updated 10 years ago
- Image size issues plugin for Burp Suite☆95Jun 27, 2018Updated 7 years ago
- Enumerating IPs in X-Forwarded-Headers to bypass 403 restrictions☆226Mar 29, 2022Updated 3 years ago
- Reverser - A Quick Reverse Connection Deployment Script☆12Jun 22, 2012Updated 13 years ago
- Cloudflare DNS Enumeration Tool for Pentesters☆524Aug 6, 2022Updated 3 years ago
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆303Feb 12, 2023Updated 3 years ago
- Second-order subdomain takeover scanner☆404Aug 28, 2025Updated 6 months ago
- bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.☆566Mar 4, 2023Updated 3 years ago
- BurpSuite extension to inject custom cross-site scripting payloads on every form/request submitted to detect blind XSS vulnerabilities☆118Dec 23, 2025Updated 2 months ago
- Burp Suite extension to generate Intruder payloads using Radamsa☆89Sep 7, 2017Updated 8 years ago
- Improved decoder for Burp Suite☆138Aug 30, 2021Updated 4 years ago
- SSRF (Server Side Request Forgery) testing resources☆2,482Oct 12, 2024Updated last year
- Leverages publicly available datasets from Google BigQuery to generate content discovery and subdomain wordlists☆767Feb 12, 2023Updated 3 years ago
- Automated blind-xss search for Burp Suite☆285Oct 10, 2019Updated 6 years ago
- Keyhack - Golang API token/webhook validator☆16Mar 20, 2025Updated 11 months ago
- Smart ssrf scanner using different methods like parameter brute forcing in post and get...☆279Feb 11, 2021Updated 5 years ago
- Generates permutations, alterations and mutations of subdomains and then resolves them☆2,477Jan 9, 2025Updated last year
- Fuzzapi is a tool used for REST API pentesting and uses API_Fuzzer gem☆667Feb 25, 2021Updated 5 years ago
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆4,123Apr 21, 2024Updated last year
- BruteXSS is a tool written in python simply to find XSS vulnerabilities in web application. This tool was originally developed by Shawar …☆561Jun 17, 2021Updated 4 years ago
- A simple CORS misconfiguration scanner☆422Aug 14, 2020Updated 5 years ago
- An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!☆2,262Mar 7, 2024Updated last year
- Fetches javascript file from a list of URLS or subdomains.☆837Jul 22, 2025Updated 7 months ago
- A tool for enumerating expired domains in CNAME records☆60Jun 30, 2016Updated 9 years ago
- A python script that finds endpoints in JavaScript files☆4,294Apr 13, 2024Updated last year
- ActionScript Proof of Concept to perform cross-domain reads☆43Aug 26, 2013Updated 12 years ago
- Paramalyzer - Burp extension for parameter analysis of large-scale web application penetration tests.☆158Jul 10, 2025Updated 7 months ago
- A simple SSRF-testing sheriff written in Go☆336Oct 31, 2024Updated last year