
CrackQL
GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

Tool to help exploit XXE vulnerabilities

A fast tool to scan CRLF vulnerability written in Go

A fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

Tool to make in memory man in the middle

SSRFuzz is a tool to find Server Side Request Forgery vulnerabilities, with CRLF chaining capabilities

Multi-threaded Go tool to detect nginx alias traversal vulnerabilities using heuristic and brute-force techniques for identifying vulnerable…

A GUI-based tool to perform security testing against the HDMI CEC (Consumer Electronics Control) and HEC (HDMI Ethernet Channel) protocols

CRLFMap is a tool to find HTTP Splitting vulnerabilities

CRLFMap is a tool to find HTTP Splitting vulnerabilities

A tool to generate and maintain wordlists for Web fuzzing.

Tool to discover paths in web applications

Automated testing to find logic and performance bugs in database systems

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

Portable debugger-based crash triage tool for fuzzing outputs. Supports parallel triage, crash deduplication, sanitizer report parsing, and multiple…

Static binary instrumentation tool that dumps COFF object files from executables, enabling code/data insertion at any location for black-box fuzzing…

Zip file format fuzzer and multi-tool.