
byp4xx
40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

Efficient and advanced man in the middle framework


:new: The Multi-Tool Web Vulnerability Scanner.

The Offensive Manual Web Application Penetration Testing Framework.

Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-…

An XSS exploitation command-line interface and payload generator.

Self contained htaccess shells and attacks

An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield

DotDotPwn - The Directory Traversal Fuzzer

This is a tool published for the Citrix ADC (NetScaler) vulnerability. We are only disclosing this due to others publishing the exploit code first.

WebPwn3r - Web Applications Security Scanner.

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…


Python codes of my blog.