mhmdiaa / second-order
Second-order subdomain takeover scanner
☆382Updated last year
Alternatives and similar repositories for second-order:
Users that are interested in second-order are comparing it to the libraries listed below
- Bugbounty scope tool☆323Updated last month
- Default signature for Jaeles Scanner☆321Updated 2 years ago
- Smart ssrf scanner using different methods like parameter brute forcing in post and get...☆276Updated 3 years ago
- Wordlists that have been compiled using Commonspeak2. This repo is updated every time new wordlists are generated.☆522Updated 6 years ago
- Generates lists of live hosts and URLs for targeting, automating the usage of MassDNS, Masscan and nmap to filter out unreachable hosts a…☆365Updated 2 years ago
- Python based scanner to find potential SSRF parameters☆303Updated 9 months ago
- An hourly updated list of subdomains gathered from certificate transparency logs☆342Updated 3 years ago
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆297Updated last year
- Simple shell script for automated domain recognition with some tools☆302Updated 4 years ago
- Monitoring framework to detect and report newly found subdomains on a specific target using various scanning tools☆269Updated 6 months ago
- You can read the writeup on this script here☆269Updated 4 years ago
- a .js scanner, built in php. designed to scrape urls and other info☆211Updated 7 years ago
- Subdomain Takeover Scanner | Subdomain Takeover Tool | by 0x94☆356Updated last year
- Takes a list of URLs and returns their HTTP response codes☆390Updated last year
- GoFingerprint is a Go tool for taking a list of target web servers and matching their HTTP responses against a user defined list of fing…☆199Updated last year
- Reconnaissance tool which scans javascript files for subdomains and then iterates over all javascript files hosted on subsequent subdomai…☆222Updated 4 years ago
- SSRF testing tool☆243Updated 2 years ago
- A DNS Bruteforcing Wordlist Generator☆350Updated last year
- Secret and/or credential patterns used for gf.☆236Updated last year
- Turbo Intruder Scripts☆220Updated 4 years ago
- The Serverless Blind XSS App☆333Updated 9 months ago
- Fetches javascript file from a list of URLS or subdomains.☆750Updated last year
- A handy DNS service written in Go to aid in the detection of several types of blind vulnerabilities. It monitors a pentester's server for…☆189Updated 4 years ago
- A Powerful Subdomain Takeover Tool☆939Updated last year
- This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes …☆256Updated 2 years ago
- Maintains a list of IPv4 DNS servers by verifying them against baseline servers, and ensuring accurate responses.☆664Updated last year
- Content discovery wordlists generated using BigQuery☆562Updated 4 years ago
- Continuous monitoring for JavaScript files☆219Updated 5 years ago
- HackerOne "in scope" domains☆419Updated this week
- This repository created for personal use and added tools from my latest blog post.☆349Updated 2 years ago