mschwager / route-detect
Find authentication (authn) and authorization (authz) security bugs in web application routes.
☆256Updated 7 months ago
Alternatives and similar repositories for route-detect:
Users that are interested in route-detect are comparing it to the libraries listed below
- FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application a…☆156Updated 3 months ago
- A smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery☆204Updated 2 months ago
- ☆180Updated 3 months ago
- Distribute ordinary bash commands over many systems☆161Updated 2 years ago
- A projectdiscovery driven attack surface monitoring bot powered by axiom☆181Updated 2 years ago
- Burp Suite extension that offers a toolkit for testing GraphQL endpoints.☆189Updated 6 months ago
- A rapid HTTP downgrade smuggling scanner written in Go.☆253Updated 9 months ago
- SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens☆152Updated 2 months ago
- PP-finder Help you find gadget for prototype pollution exploitation☆151Updated 6 months ago
- ☆164Updated 4 months ago
- ☆149Updated last year
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆622Updated last year
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆133Updated 2 months ago
- Prototype pollution scanner using headless chrome☆216Updated 2 years ago
- Find CVE PoCs on GitHub☆143Updated last year
- Automated learning of regexes for DNS discovery☆363Updated 2 years ago
- Session Hijacking Visual Exploitation☆194Updated 11 months ago
- A GraphQL enumeration and extraction tool☆130Updated 2 years ago
- ☆73Updated 7 months ago
- WhereToGo - is a list of popular services that might be used in organizations. By having an account of the user - you can try to find ent…☆119Updated 2 years ago
- A simple tool that helps to find assets/domains based on the Google Analytics ID.☆173Updated last month
- Black box fuzzer for web applications☆421Updated 7 months ago
- Made your bugbounty subdomains reconnaissance easier with Hunt3r the web application reconnaissance framework☆164Updated 2 years ago
- The AWS Enumerator was created for service enumeration and info dumping for investigations of penetration testers during Black-Box testin…☆197Updated 2 years ago
- The Template Injection Table is intended to help during the testing of an application for template injection vulnerabilities.☆69Updated 11 months ago
- Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.☆175Updated last year
- Burp Extension to add additional functionality for pentesting websocket based applications☆88Updated 8 months ago
- Discover new target domains using Content Security Policy☆393Updated this week
- Fast and customizable vulnerability scanner For JIRA written in Python☆318Updated last month
- TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines fo…☆333Updated 2 months ago