
HTB-TwoMillion-machine
Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

Automated Security Testing For REST API's

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

A Burp Extension designed to identify argument injection vulnerabilities.

Hermes Proxy - HTTP Traffic Analyzer

An on-path blackbox network traffic security testing tool

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their…

Burp Commander written in Go

Http request smuggling vulnerability scanner

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

REST/JSON API to the Burp Suite security tool.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Automatic SQL injection and database takeover tool

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…