#1Tools for testing, exploiting, and securing web applications and APIs.
Kitploit recommended

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.

Embed a reverse shell in Notion pages using the Notion API as a proxy, enabling stealthy remote shell sessions with encrypted and authenticated…

php-fpm+Nginx RCE

Proof of Concept for CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207

Detect and log CVE-2019-19781 scan and exploitation attempts.

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerabilit…

A blazing fast and fully configurable Blind SQL Injection optimization and automation framework.

Educational exploit scripts for HTTP/3 attacks (CVE-2022-30592) including HTTP3-loris, HTTP3-stream, and HTTP3-flooding, tested against QUIC-enabled…

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

Modular web application reconnaissance framework for automated subdomain enumeration, directory brute-forcing, and extraction of endpoints, JS URLs,…

Dockerized labs For Web Expert (OSWE) certification. Preparation for coming AWAE Training ...

Take a list of domains/subdomains and probe for working http/https server.

Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046

A burp suite extension that enumerates infrastructure and application admin interfaces (OTG-CONFIG-005)

Exploit using barcodes, QRcodes, earn13, datamatrix