

DotDotPwn - The Directory Traversal Fuzzer

User-Agent , X-Forwarded-For and Referer SQLI Fuzzer

A structure-aware JSON fuzzer

Command Injection Web Fuzzer Script for mitmproxy


Weaponizing WaybackUrls for Recon, BugBounties , OSINT, Sensitive Endpoints and what not

Go Web Application Penetration Test

Burp Suite extension to generate Intruder payloads using Radamsa

Automatic SQL injection and database takeover tool

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor…

A next-generation crawling and spidering framework.

Curated archive of public proof-of-concept exploits and vulnerability research writeups covering web, binary, and network security, with a focus on…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.