patuuh / Payloads-and-wordlistsLinks
List of payloads for BurpSuite intruder. Payloads gathered from Swisskyrepos PayloadsAllTheThings
☆34Updated last week
Alternatives and similar repositories for Payloads-and-wordlists
Users that are interested in Payloads-and-wordlists are comparing it to the libraries listed below
Sorting:
- A burp suite extension that reviews backup, old, temporary and unreferenced files on web server for sensitive information (OWASP WSTG-CON…☆163Updated last year
- A Proof of Concept for Clickjacking Attacks☆57Updated 4 years ago
- Learn how to automate XSS, SSRF, LFI, SQLI, NoSQLi☆44Updated 4 years ago
- Enumerate old versions of robots.txt paths using Wayback Machine for content discovery☆53Updated 2 years ago
- Describe how to use ffuf different options with examples☆90Updated 3 years ago
- A tool that automates the search for IDOR vulnerabilities in web apps and APIs☆63Updated 4 years ago
- A command-line utility designed to discover subdomains for a given domain in a simple, efficient way. It works by gathering information f…☆115Updated last month
- The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489☆31Updated last year
- ☆86Updated 3 years ago
- The fastest way to setup XSSHunter. It has options for the official and Discord/Slack Forks☆45Updated last year
- Wordlist for web fuzzing, made from a variety of reliable sources including: result from my pentests, git.rip, ChatGPT, Lex, nuclei templ…☆104Updated 2 months ago
- CVE Collection of jQuery XSS Payloads☆75Updated 3 years ago
- ☆174Updated last month
- A path-normalization pentesting tool.☆135Updated 3 months ago
- 403-bypass tool to bypass 403 responses.☆124Updated 2 years ago
- Tool to create XSS PDF files☆67Updated last year
- Find subdomains on GitLab.☆103Updated last year
- ☆67Updated 2 years ago
- Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.☆46Updated last year
- Here Are Some Bug Bounty Resource From Twitter☆105Updated 7 months ago
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.☆83Updated 2 years ago
- Log4jScanner is a Log4j Related CVEs Scanner, Designed to Help Penetration Testers to Perform Black Box Testing on given subdomains.☆49Updated 4 months ago
- Scanner Tool For XSS Vulnerability☆83Updated 3 years ago
- HTTP verb tampering & methods enumeration☆65Updated 5 months ago
- ParamFirstCheck identifies in a list of urls those containing a parameter of the top 25 of the most vulnerable parameters for SQLi, LFI, …☆34Updated 2 years ago
- Enumerate Subdomains Through Google Dorks (Bypassed Page Filter)☆125Updated 6 months ago
- ☆117Updated 3 years ago
- BChecks collection for Burp Suite Professional☆101Updated last year
- A Complete SSRF (Server Side Request Forgery) Scanner.☆41Updated last month
- Fast Bug Bounty Script☆40Updated 11 months ago