themalwarenews / headerinjectionLinks
This script identifies Host Header Injection vulnerabilities in a list of URLs or a specific domain, outputting the vulnerable locations along with the specific headers causing the vulnerability
☆15Updated 2 years ago
Alternatives and similar repositories for headerinjection
Users that are interested in headerinjection are comparing it to the libraries listed below
Sorting:
- A solid recon tool I use personally.☆30Updated 2 years ago
 - Automate bug bounty recon using bash alias☆15Updated last year
 - Programs I Made while learning python for pentesters.☆19Updated 3 years ago
 - ☆15Updated 2 years ago
 - A repo for tools, utils, and wrappers that are to small to put in their own repo.☆23Updated 2 years ago
 - ☆13Updated 3 years ago
 - ☆16Updated last year
 - XSS Finder Via SSTI☆57Updated 2 years ago
 - Filter URLs to save your time.☆60Updated 3 years ago
 - ☆19Updated 4 years ago
 - Enhanced 403 bypass header☆21Updated 3 years ago
 - An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆17Updated 4 years ago
 - Quick tool to create custom wordlists like how fuzzers work☆10Updated 2 years ago
 - Xss payload for bypassing waf☆18Updated 5 years ago
 - a burp extension for dynamic payload generation to detect injection flaws (RCE, LFI, SQLi), creates access matrix based user sessions to …☆49Updated 3 years ago
 - Striping CDN & WAF IPs from a list of IP Addresses☆79Updated 5 months ago
 - Tool for testing reflections in the HTTP responses☆60Updated 2 years ago
 - Tool for fetching all the available waybackmachine snapshot urls☆24Updated last year
 - Cool One Liners at one place to make your recon and bug bounty skills better !☆14Updated 5 years ago
 - Check if domain has bug bounty program or not☆28Updated 2 years ago
 - I collected it to help the bug hunter get a reward☆58Updated 3 years ago
 - bash script for automating subdomain enumeration process either passive or active☆29Updated 10 months ago
 - Find CVEs that don't have a Detectify modules.☆22Updated 2 years ago
 - Python script implementing the favicon hash trick to find subdomains.☆37Updated 2 years ago
 - ☆15Updated 2 years ago
 - An SSRF detector tool written in golang. I have fixed some errors and added some more payloads to it. But the tool credits go to z0idsec.☆45Updated 4 years ago
 - JsValidator is a tool created for validating the JS files after crawlling it from waybackurls☆19Updated 2 years ago
 - ☆18Updated 3 months ago
 - A simple tool which makes creating nuclei templates even easier.☆36Updated last year
 - In this repo, I have created a subdomain enumeration function that grab subdomains in deep.☆22Updated 2 years ago