
CredMaster
Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

A modern vulnerable web app

An intentionally designed broken web application based on REST API.

Tests your WAF with +160 payloads

a Damn Vulnerable Serverless Application

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

SAML2 Burp Extension

Research on GraphQL from an AppSec point of view.


GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

A rapid HTTP downgrade smuggling scanner written in Go.

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

Http request smuggling vulnerability scanner

Academic purposes only. Attack against Salesforce lightning with guest privilege.

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977

Python PoC validating unauthenticated BookingPress Pro REST API exposure and checking for exposed booking/customer data with configurable request…

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions