
skipfish
Web application security scanner created by lcamtuf for google - Unofficial Mirror

Web application security scanner created by lcamtuf for google - Unofficial Mirror

BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…

Automated web vulnerability scanner combining URL discovery tools (ParamSpider, waybackurls, gauplus, hakrawler, katana) with Nuclei fuzzing…

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

XSS spider - 66/66 wavsep XSS detected

An automatic XSS discovery tool

A guided mutation-based fuzzer for ML-based Web Application Firewalls

A wordlist of API names for web application assessments

Go Web Application Penetration Test

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Exploit for CVE-2024-5124 targeting ChuanhuChatGPT via TLS timing side-channel attack. Uses tlsfuzzer to perform character-by-character credential…

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

Command Injection Web Fuzzer Script for mitmproxy

Python exploit for CVE-2019-5096, a use-after-free vulnerability in GoAhead web server's upload handler, causing denial of service via double-free.

Coverage-guided fuzzer that uses taint tracking and scalar optimization to solve path constraints without symbolic execution, improving branch…

A structure-aware JSON fuzzer