
cloud-buster
A Cloudflare resolver that works

A Cloudflare resolver that works

A list of resources for those interested in getting started in bug bounties

ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup

Git All the Payloads! A collection of web attack payloads.

Penetration tests guide based on OWASP including test cases, resources and examples.

🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.


python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

A fast WordPress plugin enumeration tool

Advanced cross-platform web crawler for security professionals, enabling automated reconnaissance, information gathering, and OSINT data collection…

Automatically Launch Google Hacking Queries Against A Target Domain

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

「🔑」A tool used to hunt down API key leaks in JS files and pages

Selenium powered Python script to automate searching for vulnerable web apps.