trufflesecurity / of-CORSView external linksLinks
☆154Aug 18, 2023Updated 2 years ago
Alternatives and similar repositories for of-CORS
Users that are interested in of-CORS are comparing it to the libraries listed below
Sorting:
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆148Dec 9, 2024Updated last year
- Unleash the power of cloud☆821Nov 19, 2024Updated last year
- Filter and enrich a list of subdomains by level☆210Sep 25, 2023Updated 2 years ago
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆721Feb 3, 2026Updated 2 weeks ago
- Rust-based high performance domain permutation generator.☆297Dec 2, 2023Updated 2 years ago
- Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes☆32Dec 10, 2022Updated 3 years ago
- REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications☆1,288Aug 7, 2025Updated 6 months ago
- Declutters URLs in a fast and flexible way, for improving input for web hacking automations such as crawlers and vulnerability scans.☆59Jan 22, 2023Updated 3 years ago
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆52Sep 11, 2024Updated last year
- Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!☆973Jan 12, 2024Updated 2 years ago
- A cybersecurity challenge, based on a real world finding☆12Jul 11, 2024Updated last year
- Burp Suite extension that offers a toolkit for testing GraphQL endpoints.☆203Aug 5, 2024Updated last year
- A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidde…☆434Oct 16, 2025Updated 4 months ago
- A Canary which fires when uninstalled☆34Mar 16, 2021Updated 4 years ago
- declutters url lists for crawling/pentesting☆1,524Feb 23, 2025Updated 11 months ago
- ☆520Apr 29, 2024Updated last year
- Making Favicon.ico based Recon Great again !☆1,261Aug 29, 2023Updated 2 years ago
- De-clutter a list of URLs☆384Feb 3, 2026Updated 2 weeks ago
- Find related domains of a given domain.☆103Aug 5, 2023Updated 2 years ago
- Golang tool which helps dropping the irrelevant entries from your ffuf result file.☆141Sep 16, 2024Updated last year
- Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!☆1,264Updated this week
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆36Mar 4, 2025Updated 11 months ago
- ☆16Dec 7, 2025Updated 2 months ago
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆749Dec 19, 2023Updated 2 years ago
- Leverages B64 chunks to split files and save to clipboard☆26Dec 7, 2025Updated 2 months ago
- A rapid HTTP downgrade smuggling scanner written in Go.☆313May 16, 2024Updated last year
- Hidden parameters discovery suite☆2,015Sep 8, 2024Updated last year
- ☆105Jan 3, 2023Updated 3 years ago
- Web cache poisoning vulnerability scanner.☆72May 5, 2022Updated 3 years ago
- Discover new target domains using Content Security Policy☆501Feb 7, 2026Updated last week
- Extract URLs, paths, secrets, and other interesting bits from JavaScript☆1,755May 22, 2024Updated last year
- Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load☆297Sep 22, 2024Updated last year
- A list of "secrets" from JWT sample code and readme files.☆57Oct 28, 2020Updated 5 years ago
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations☆85Updated this week
- Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!☆2,533Feb 7, 2026Updated last week
- Community curated list of nuclei templates for finding "unknown" security vulnerabilities.☆87May 2, 2024Updated last year
- 🔭 Collection of regexp pattern for security passive scanning☆116Feb 18, 2023Updated 2 years ago
- Recurrent Neural Network SubDomain Discovery Tool☆95Sep 20, 2022Updated 3 years ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆282Sep 11, 2025Updated 5 months ago