roottusk / xforwardy
Host Header Injection Scanner
☆44Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for xforwardy
- The objective of this Burp Suite extension is the flexible and dynamic extraction, correlation, and structured presentation of informatio…☆54Updated last year
- Shodan Favicon Hash Generator By Aziz Hakim @eternyle☆24Updated 5 months ago
- Blind spot is a python tool for blind injection vulnerabilities , SQLi time based , Command injection , code injection , SSTI☆27Updated 3 years ago
- A Payload Injector for bugbounties written in go☆71Updated 4 years ago
- All known and unknown public POC's for wordpress themes and plugins☆78Updated 3 years ago
- Messy BurpSuite plugin for SQL Truncation vulnerabilities.☆61Updated 4 years ago
- Related subdomains finder☆29Updated 2 years ago
- An SSRF detector tool written in golang. I have fixed some errors and added some more payloads to it. But the tool credits go to z0idsec.☆43Updated 3 years ago
- A Python based scanner to find potential SSRF parameters in a web application.☆71Updated 3 years ago
- My Tools For Bug Bounty☆63Updated last month
- Extract endpoints marked as disallow in robots files to generate wordlists.☆54Updated 2 years ago
- A simple Bash one liner with aim to automate CRLF vulnerability scanning.☆68Updated 4 years ago
- Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities☆41Updated last year
- Dump all available paths and/or endpoints on WADL file.☆90Updated 2 weeks ago
- Bucket Flaws ( S3 Bucket Mass Scanner ): A Simple Lightweight Script to Check for Common S3 Bucket Misconfigurations☆57Updated 4 years ago
- SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files☆36Updated 3 years ago
- A Web-UI for subdomain enumeration (subfinder)☆53Updated 4 years ago
- Given a list of domains, you resolve them and get the IP addresses.☆47Updated 2 years ago
- golang tool to scan domains or single domains with know security issues against xmlrpc☆59Updated last year
- Tool to automate recon☆41Updated 2 years ago
- Host Header Injection Checker☆79Updated 2 years ago
- A simple reconnaissance framework for bug bounty hunting☆35Updated 4 years ago
- Virtual host wordlist☆51Updated 3 years ago
- Tool to generate csrf payloads based on vulnerable requests☆61Updated 4 years ago
- Web application recon for bug bounty☆21Updated 4 years ago
- Alternative to XSS Hunter for blind XSS.☆48Updated last year
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆58Updated 3 years ago
- A tool for testing subdomain takeover possibilities at a mass scale.☆48Updated 3 years ago