🏴☠️ Bypass Same Origin Policy with DNS-rebinding to retrieve local server files 🏴☠️
☆204Feb 26, 2019Updated 7 years ago
Alternatives and similar repositories for ByP-SOP
Users that are interested in ByP-SOP are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- jsonp is a Burp Extension which attempts to reveal JSONP functionality behind JSON endpoints.☆154Feb 15, 2021Updated 5 years ago
- A better dns bruteforcer written in golang☆13Nov 4, 2018Updated 7 years ago
- All about CVE-2018-14667; From what it is to how to successfully exploit it.☆50Nov 30, 2018Updated 7 years ago
- SSRF (Server Side Request Forgery) testing resources☆2,494Oct 12, 2024Updated last year
- CTF Writeups☆12Feb 25, 2023Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- DNS rebinding toolkit☆254May 22, 2023Updated 3 years ago
- A blind XXE injection callback handler. Uses HTTP and FTP to extract information. Originally written in Ruby by ONsec-Lab.☆519Jul 29, 2020Updated 5 years ago
- List DTDs and generate XXE payloads using those local DTDs.☆659Feb 21, 2024Updated 2 years ago
- Burp extension to detect alias traversal via NGINX misconfiguration at scale.☆265Nov 18, 2021Updated 4 years ago
- A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques☆742May 4, 2019Updated 7 years ago
- Use HTTP Smuggling Lab to learn HTTP Smuggling.☆347Nov 20, 2022Updated 3 years ago
- Deeplack is a python script designed for comparing images (screenshots) using DeepAI to detect changes on websites.☆14Jun 19, 2019Updated 6 years ago
- Reverse engineers GQL Schema and generates template payloads☆46Apr 5, 2019Updated 7 years ago
- A tool that can help detect and takeover subdomains with dead DNS records☆12Aug 23, 2018Updated 7 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- DNS Rebinding Exploitation Framework☆492Apr 27, 2021Updated 5 years ago
- Stealing CSRF tokens with CSS injection (without iFrames)☆324Feb 7, 2018Updated 8 years ago
- A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)☆684Jan 28, 2024Updated 2 years ago
- Extract relative urls from a heap snapshot☆87May 30, 2021Updated 4 years ago
- DOM XSS scanner for Single Page Applications☆415Nov 15, 2025Updated 6 months ago
- ☆162Dec 7, 2017Updated 8 years ago
- ☆93Sep 18, 2021Updated 4 years ago
- Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.☆616Mar 4, 2021Updated 5 years ago
- VyAPI - A cloud based vulnerable hybrid Android App☆86Feb 21, 2020Updated 6 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆72Nov 20, 2017Updated 8 years ago
- AWS S3 Bucket Finder.☆14Oct 28, 2025Updated 6 months ago
- Prototype Pollution and useful Script Gadgets☆1,623Jan 27, 2024Updated 2 years ago
- A highly configurable Framework for easy automated web scanning☆383Jul 13, 2020Updated 5 years ago
- Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the ac…☆1,802Apr 26, 2024Updated 2 years ago
- Some tools to automate recon - 003random☆295Jun 5, 2018Updated 7 years ago
- Nuclei is a fast tool for configurable targeted vulnerability scanning based on templates offering massive extensibility and ease of use.☆15Aug 4, 2025Updated 9 months ago
- A mini webserver with FTP support for XXE payloads☆343Jan 3, 2024Updated 2 years ago
- A tool for embedding XXE/XML exploits into different filetypes☆1,171Dec 16, 2024Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- This is a web application fuzzer scanner - the goal was CLI flexibility and rapid prototyping☆48Nov 12, 2019Updated 6 years ago
- The cheat sheet about Java Deserialization vulnerabilities☆3,177May 26, 2023Updated 2 years ago
- A simple CORS misconfiguration scanner☆424Aug 14, 2020Updated 5 years ago
- MalRecon - Basic Malware Reconnaissance and Analysis Tool☆26Jun 8, 2017Updated 8 years ago
- DupeKeyInjector☆134Apr 16, 2022Updated 4 years ago
- List of Google Dorks for sites that have responsible disclosure program / bug bounty program☆22Sep 8, 2019Updated 6 years ago
- A front-end JavaScript toolkit for creating DNS rebinding attacks.☆45Jun 19, 2018Updated 7 years ago