shreyaschavhan / payloads
A list of useful payloads and bypass for Web Application Security
☆11Updated last year
Alternatives and similar repositories for payloads:
Users that are interested in payloads are comparing it to the libraries listed below
- Find CVEs that don't have a Detectify modules.☆21Updated last year
- ☆12Updated 3 years ago
- Scripts/tools to destroy things☆16Updated 3 years ago
- collection of various grep patterns collected from tomnomnom/gf and other places☆21Updated 4 years ago
- Enhanced 403 bypass header☆21Updated 2 years ago
- H&E- Burp Highlighter and Extractor☆18Updated last year
- CRLFMap is a tool to find HTTP Splitting vulnerabilities☆34Updated 4 years ago
- List of custom Nuclei templates☆15Updated last year
- ☆11Updated last year
- Credax - Fuzzing Tool with Slack Notifications. Also removes false positive responses.☆10Updated 3 years ago
- Gampung tools for find nuclei template from github☆10Updated last year
- ☆14Updated 10 months ago
- Small python or powershell script to look for potential subdomain takeover vulnerabilities via vulnerable Alias.☆8Updated 3 years ago
- offy is a tool for bugbounty hunters to save money in their EC2 instances☆13Updated last year
- ☆21Updated 4 years ago
- ☆14Updated last year
- Parameter-Reflect-Finder is a python based tool that helps you find reflected parameters which can have potential XSS or Open redirection…☆15Updated 2 years ago
- Ffuf output browser☆39Updated last year
- ☆13Updated 10 months ago
- qsinject (Query String Inject) is a tool that allows you to quickly substitute query string values with regex matches, one-at-a-time.☆30Updated 4 years ago
- Saves pages to Wayback machine☆13Updated 2 months ago
- parse ffuf & map endpoints to wordlists☆20Updated 3 years ago
- Blind spot is a python tool for blind injection vulnerabilities , SQLi time based , Command injection , code injection , SSTI☆27Updated 4 years ago
- A BurpSuite plugin for BBRF☆24Updated 3 months ago
- Wounty is a simple web enumeration script that makes use of other popular tools to automate the early stages of recognition in Bug Bounty…☆14Updated 3 years ago
- (Mass) Mining parameters from dark corners of Web Archives☆1Updated last year
- My fuzz repo!☆22Updated last year
- recon.cloud is website that scans AWS, Azure and GCP public cloud footprint this GO tool only utilize its API for getting result to termi…☆23Updated 2 years ago
- gup aka Get All Urls parameters to create wordlists for brute forcing parameters.☆17Updated 3 years ago
- An Vulnerability detection and Exploitation tool for CVE-2024-24919☆23Updated 8 months ago