r0oth3x49 / Xpath
A python based cross-platform tool that automates the process of detecting and exploiting error-based injection security flaws.
☆137Updated 2 years ago
Alternatives and similar repositories for Xpath:
Users that are interested in Xpath are comparing it to the libraries listed below
- Bypassing-Web-Application-Firewalls-And-XSS-Filters A series of python scripts for generating weird character combinations and lists for…☆144Updated 4 years ago
- Bypassing WAF by abusing SSL/TLS Ciphers☆311Updated 3 years ago
- Toolset for detecting reflected xss in websites☆110Updated 6 years ago
- A simple XSS finding tool☆109Updated 6 years ago
- A script to extract domain names from Content Security Policy(CSP) headers☆108Updated 5 years ago
- CVE-2017-9506 - SSRF☆188Updated 2 years ago
- BugBounty Tool☆40Updated 5 years ago
- Burp Suite extension to discover assets from HTTP response.☆220Updated 3 years ago
- A tool to hunt for publicly accessible DigitalOcean Spaces☆154Updated 4 years ago
- A Python script to parse net blocks & domain names from SPF record☆82Updated 4 years ago
- Wordlist for content(directory) bruteforce discovering with Burp or dirsearch☆212Updated 3 months ago
- Convert your masscan/subdomain-scan results (80,443,8080) into screenshots for better analysis☆36Updated 6 years ago
- This Repo contains wordlist for subdomain enumeration , php file path, html file path, and js file path☆102Updated 4 years ago
- subdomain bruteforce list☆100Updated 3 months ago
- Resolve and quickly portscan a list of (sub)domains.☆86Updated 8 years ago
- Jsdir is a Burp Suite extension that extracts hidden paths from js files and beautifies it for further reading.☆118Updated 4 years ago
- File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.☆267Updated 3 years ago
- Burp Suite extension to easily export sub domains☆44Updated 5 years ago
- Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that improve an active and passive scanner by yourself. This …☆60Updated 3 years ago
- Powerful Visual Subdomain Enumeration at the Click of a Mouse☆138Updated 5 years ago
- dork scanner with Sqli and Lfi testing☆29Updated 6 years ago
- A Burp Extension to test applications for vulnerability to the Web Cache Deception attack☆136Updated 3 years ago
- Hacking tools☆143Updated 2 months ago
- A tool to find sensitive keys and passwords in Travis logs☆141Updated 3 years ago
- Automatically forward HTTP GET & POST requests to SQLMap's API to test for SQLi and XSS☆83Updated 2 years ago
- Automated client-side template injection (sandbox escape/bypass) detection for AngularJS v1.x.☆307Updated 3 years ago
- Local File Inclusion Exploitation Tool (mirror)☆124Updated 7 years ago