
api_wordlist
A wordlist of API names for web application assessments

A wordlist of API names for web application assessments

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Burp Extension for collaboration in Faraday

Web app authorisation coverage scanning

Tests your WAF with +160 payloads

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Demonstrates an IDOR vulnerability in TelegAI's chat API allowing unauthorized conversation tampering, leading to phishing and XSS-based account…

a Damn Vulnerable Serverless Application

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

Damn Vulnerable C# Application (API)

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.