XSS-Freak is an xss scanner fully written in python3 from scratch. it is one of its kind since it crawls the website for all possible links and directories to expand its attack scope. then it searches them for inputs tags and then launches a bunch of xss payloads. if an inputs is not sanitized and vulnerable to xss attacks, the tool will discov…
☆15Nov 25, 2019Updated 6 years ago
Alternatives and similar repositories for XSS-Freak
Users that are interested in XSS-Freak are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Extract domain from SSL Information☆15Nov 23, 2021Updated 4 years ago
- Automate bug bounty recon using bash alias☆15Aug 6, 2024Updated 2 years ago
- This is a hash parser that will export a rc file compatible with Metasploit. This is useful when compromising a separate domain and want …☆24Oct 8, 2014Updated 11 years ago
- Sec-Payloads, It's a collection of multiple types of lists used during security assessments & used for bug bounty hunting or penetration …☆10Nov 17, 2025Updated 9 months ago
- ☆17Feb 22, 2020Updated 6 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Light System Examination Toolkit (LISET) - logs & activity & configuration gathering utility that comes handy in fast Windows incident re…☆32Aug 29, 2016Updated 10 years ago
- XSSB is a proactive DOM sanitizer, defending against client-side injection attacks!☆38Aug 26, 2018Updated 8 years ago
- Tool to find stored robots.txt files from the past☆20Jun 4, 2023Updated 3 years ago
- Simple tmux session management.☆17Dec 16, 2023Updated 2 years ago
- Simple tools to handle string and generate subdomain permutations☆15Jun 8, 2022Updated 4 years ago
- Manage Engine Decrypter☆29Oct 17, 2022Updated 3 years ago
- Enhanced 403 bypass header☆21Sep 12, 2022Updated 3 years ago
- ☆33Jul 20, 2021Updated 5 years ago
- Seven different DLL injection techniques in one single project.☆12May 19, 2020Updated 6 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Path traversal / LFI fuzzer in Go - 66 encoding bypass techniques, response analysis, goroutine concurrency, wordlist support, proxy (Bur…☆16Apr 10, 2026Updated 4 months ago
- Returns disallowed paths from robots.txt found on your target domain and snapshotted by the Wayback Machine☆28Jul 18, 2025Updated last year
- BurpSuite Extension leveraging new Montoya API to automatically sets payload positions to your inruder tab saving you time during VAPT.☆19Feb 21, 2026Updated 6 months ago
- ex-redirect — An automated open redirect scanner using Wayback Machine archives. Supports subdomain grouping, live URL filtering, and Wor…☆15May 9, 2025Updated last year
- [Forked] This repo is for learning various heap exploitation techniques.☆10Sep 6, 2018Updated 8 years ago
- Repository for qTox nightly builds☆11May 4, 2021Updated 5 years ago
- Accompanying code for blog post "Mapping iOS Persistence Attack Surface using Corellium"☆11Jun 10, 2025Updated last year
- This script scrapes the list of open Bug Bounty Programs from openbugbounty.org☆28Mar 22, 2022Updated 4 years ago
- Automatically exported from code.google.com/p/jamaal-re-tools☆13Oct 4, 2015Updated 10 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- XSS-Freak is an xss scanner fully written in python3 from scratch. it is one of its kind since it crawls the website for all possible lin…☆29Feb 15, 2020Updated 6 years ago
- CloudHound is a cloudflare bypass tool which is using several methods such as DNS history Checkup, Cross-Site port Attack and etc to dete…☆19Apr 19, 2023Updated 3 years ago
- Find alive host from dumped subdomains, huge domain list , alive subdomains☆26Mar 29, 2021Updated 5 years ago
- WPScan is a black box WordPress vulnerability scanner.☆10Oct 6, 2017Updated 8 years ago
- A Powershell script that looks for specific emails in an exchange users mailbox, downloads the attachments, then marks those emails as re…☆17Apr 22, 2024Updated 2 years ago
- HTB Jail Remote Exploit By Cneeliz - 2017☆15Jan 9, 2018Updated 8 years ago
- Tool to remove unsupported arm64e slice from a dylib based on the iOS version☆13Dec 21, 2022Updated 3 years ago
- Patching ngrok macOS arm64 binary to run on iOS☆12May 31, 2022Updated 4 years ago
- TProx is a fast reverse proxy path traversal detector and directory bruteforcer.☆30Sep 16, 2021Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A Post-exploitation Toolset for Interacting with the Microsoft Graph API☆13Nov 1, 2023Updated 2 years ago
- A ruby self contained, low resource consuming HTTP transparent proxy designed for the WiFi Pineapple MKV.☆17Jun 29, 2015Updated 11 years ago
- XSS scanner tool to scan a list of URLs provided in a .txt file for reflected XSS(rxss) vulnerabilities. This tool is designed to efficie…☆14Jun 29, 2024Updated 2 years ago
- An automated bug hunting tool for comprehensive reconnaissance, including subdomain enumeration, port scanning, vulnerability detection, …☆17Jun 24, 2025Updated last year
- Auth Mutator is a Burp Suite extension that helps you experiment with mutated authentication requests while keeping the original traffic …☆16Updated this week
- HackSys Extreme Vulnerable Driver - Various Windows 7 x86 Kernel Exploits☆20Jan 13, 2018Updated 8 years ago
- XSS payloads for bypassing WAF. This repository is updating continuously.☆10Aug 8, 2021Updated 5 years ago