
S3Scanner
Scan for misconfigured S3 buckets across S3-compatible APIs!

Scan for misconfigured S3 buckets across S3-compatible APIs!

This tool is designed to scan and identify whether a website has an exposed ".git" directory, which may contain sensitive information such as source…

Multi-threaded Python tool to extract exposed .git directories from websites, recursively downloading files and identifying SHA-1 hashes for source…

🦁 Python project to identify and scan for vulnerabilities related to the Joomla CMS project. It scans for common misconfigurations and public…

A tool to scan Kubernetes cluster for risky permissions

CLI tool to detect CGI printenv information disclosure vulnerability in web servers. Scans single URLs or lists, supports Telegram alerts and output…

Automated scanner for common Nginx misconfigurations and vulnerabilities, including CRLF injection, path traversal, variable leakage, and…

Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

Scan publicly accessible assets on your AWS cloud environment

Windows Batch Scrip to Fix the log4j-issue-CVE-2021-44228

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

Proof-of-concept exploit for CVE-2021-3019, a directory traversal vulnerability in LanProxy 0.1 that allows reading configuration files to obtain…

Automated brute-force tool for enumerating ServiceNow articles to detect misconfigurations that could leak sensitive data via unauthenticated access.

Python script to scan shared hosting environments for vulnerable .htaccess configurations (CVE-2017-9798), exiting with code 1 upon detection.

Subdomain brute-forcing tool that enumerates existing subdomains and detects misconfigured cloud-hosted subdomains vulnerable to takeover across AWS,…