
jaeles
The Swiss Army knife for automated Web Application Testing

The Swiss Army knife for automated Web Application Testing

Detect and bypass web application firewalls and protection systems

A wordlist of API names for web application assessments

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Web Application Vulnerability Scanner.

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute arbitrary javascript or HTML…

Web Application Exploit Development

This PoC script is designed to verify the presence of CVE-2024-9326, a high SQL Injection vulnerability in PHPGurukul Online Shopping Portal v2.0. It…

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Python-based scanner that detects debug mode misconfigurations in web applications using multiple HTTP methods and fingerprinting techniques to…

Web app authorisation coverage scanning

Tests your WAF with +160 payloads