thehlopster / hfuzz
Wordlist for web fuzzing, made from a variety of reliable sources including: result from my pentests, git.rip, ChatGPT, Lex, nuclei templates, web-scanners, seclist, bo0m, and more.
☆96Updated 3 weeks ago
Alternatives and similar repositories for hfuzz:
Users that are interested in hfuzz are comparing it to the libraries listed below
- Simplify your life with leak detection in JavaScript. NipeJS streamlines the use of regex, making it effortless to uncover potential leak…☆90Updated 6 months ago
- CVE Collection of jQuery UI XSS Payloads☆118Updated 2 years ago
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.☆75Updated last year
- Private Nuclei Templates☆97Updated last week
- ☆118Updated last year
- ☆69Updated 2 years ago
- ☆130Updated 3 months ago
- A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing☆139Updated last year
- Unofficial Acunetix CLI tool for automated pentesting and bug hunting across large scopes.☆80Updated last year
- Self-hosted passive subdomain continous monitoring tool.☆160Updated last year
- A Burp Suite extension to extract datas from source code while browsing.☆154Updated 11 months ago
- This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.☆239Updated last year
- ☆235Updated 3 years ago
- unleashed ffuf☆111Updated 8 months ago
- All Type of Payloads☆132Updated 11 months ago
- ☆66Updated last year
- Make URL path combinations using a wordlist☆173Updated last year
- ☆155Updated last year
- BChecks collection for Burp Suite Professional☆93Updated 8 months ago
- Automated Tool for Testing Header Based Blind SQL Injection☆271Updated last year
- Community curated list of nuclei templates for finding "unknown" security vulnerabilities.☆36Updated 7 months ago
- A path-normalization pentesting tool.☆122Updated last year
- EndExt is a .go tool for extracting all the possible endpoints from the JS files☆195Updated 7 months ago
- A standalone Blind XSS Script.☆47Updated 2 years ago
- Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.☆44Updated last year
- Custom scan profiles for use with Burp Suite Pro☆122Updated 11 months ago
- Describe how to use ffuf different options with examples☆84Updated 2 years ago
- A collection oneliner scripts for bug bounty☆173Updated 11 months ago
- Go scanner to find web cache poisoning vulnerabilities in a list of URLs☆135Updated last year
- Parse FFUF results in GUI with option to sort based by response code , size , keyword☆94Updated 5 months ago