π Websheep is an app based on a willingly vulnerable ReSTful APIs.
β59Mar 25, 2024Updated 2 years ago
Alternatives and similar repositories for websheep
Users that are interested in websheep are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- β91May 1, 2023Updated 3 years ago
- The Pixi module is a MEAN Stack web app with wildly insecure APIs!β140Dec 22, 2022Updated 3 years ago
- Damn Vulnerable Web Services is a vulnerable application with a web service and an API that can be used to learn about webservices/API reβ¦β512Mar 29, 2026Updated 3 months ago
- A very vulnerable implementation of a GraphQL API.β62Nov 12, 2021Updated 4 years ago
- This is vulnerable microservice written in many language to demonstrating OWASP API Top Security Risk (under development)β47Feb 2, 2023Updated 3 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer β’ AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Vulnerable REST API with OWASP top 10 vulnerabilities for security testingβ1,277Apr 7, 2026Updated 3 months ago
- Intentionaly very vulnerable API with bonus bad coding practicesβ54Nov 15, 2025Updated 8 months ago
- completely ridiculous API (crAPI)β1,549May 14, 2026Updated 2 months ago
- A simple Node.js Express REST app with some OWASP vulnerabilities.β25May 14, 2026Updated 2 months ago
- vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.β1,345Jan 10, 2025Updated last year
- β433Aug 13, 2022Updated 3 years ago
- Vulnerable APIβ426Mar 4, 2023Updated 3 years ago
- A burpsuite extension that helps security researchers find public security reports published on h1 based on the selected hostβ43May 9, 2020Updated 6 years ago
- β21Mar 27, 2026Updated 3 months ago
- Managed Database hosting by DigitalOcean β’ AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Automated Linux service that collects information on local Wi-Fi networks and performs deauthentication attacks.β69Mar 4, 2023Updated 3 years ago
- Monitor your target continuously for new subdomains!β25Mar 18, 2023Updated 3 years ago
- Bypassing AV, EDR, Application Whitelisting and ASR Rulesβ13Apr 18, 2023Updated 3 years ago
- A lab to play with authentication and authorisation problemsβ98Mar 7, 2023Updated 3 years ago
- Magento Security Scannerβ13Jan 10, 2022Updated 4 years ago
- This repository contains an example Python API that is vulnerable to several different web API attacks.β70Feb 7, 2024Updated 2 years ago
- SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in β¦β16Jan 8, 2019Updated 7 years ago
- β15Sep 4, 2025Updated 10 months ago
- Burp Suite extension for parsing Swagger web service definition filesβ20Jul 15, 2025Updated last year
- End-to-end encrypted email - Proton Mail β’ AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Custom scripts used during the scenarioβ21Apr 5, 2021Updated 5 years ago
- Converts John The Ripper/Cain format hashes (singular, or in bulk) to HashCat compatible hash format.β36Nov 24, 2019Updated 6 years ago
- Plattform to develop and experiment with existing java web attacks.β32Jan 8, 2018Updated 8 years ago
- C2 Framework - Advanced Red Team Toolβ21Jun 1, 2026Updated last month
- Parse OpenAPI specifications, previously known as Swagger specifications, into the BurpSuite for automating RESTful API testing β approveβ¦β48Feb 22, 2024Updated 2 years ago
- Mishky's AD Range & The Escalation Path from Hellβ19Jan 16, 2025Updated last year
- Damn Vulnerable Web Services is an insecure web application with multiple vulnerable web service components that can be used to learn reaβ¦β460Dec 6, 2021Updated 4 years ago
- Removes duplicate entries from a file, resulting in only unique parameter combinations. Useful for parsing waybackurls and making recon mβ¦β12May 31, 2020Updated 6 years ago
- Extract metadata with SSRF (Server-Side Request Forgery)β16Jul 23, 2022Updated 4 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits β’ AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Sharing Various Thingsβ21Jun 28, 2022Updated 4 years ago
- Vulnerable Banking Suiteβ173Sep 29, 2025Updated 9 months ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.β32Jun 22, 2023Updated 3 years ago
- Contextual Content Discovery Toolβ3,233Jul 10, 2026Updated 2 weeks ago
- A small and dirty python3 based script to download courses from Infosec Institute.β12Oct 6, 2021Updated 4 years ago
- NestJs module to easily implement event driven architecture using RxJs in any NestJs projectβ10Apr 1, 2022Updated 4 years ago
- Scan Google Maps Api Keys and see which services you can use. Original codebase from ozguralp/gmapsapiscannerβ30Nov 18, 2021Updated 4 years ago