
lazyrecon
Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

Proof-of-concept for CVE-2023-0860, demonstrating unauthenticated brute-force login attacks on Modoboa Mail Hosting and Management before v2.0.3.

A web front-end for password cracking and analytics

🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.

This tool tests WordPress installations for XML-RPC authentication vulnerabilities.

Arkhota, a web brute forcer for Android.


Simple brute force tool for Telkom Indonesia's ZTE F609 routers

Brute-force tool for discovering hidden GET and POST parameters in web applications, supporting custom wordlists and concurrent requests.

Directory/Subdomain scanner developed in GoLang.

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

This tool can be used to brute discover GET and POST parameters

Smart ssrf scanner using different methods like parameter brute forcing in post and get...

All-in-One Toolkit for BruteForce Attacks

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Brute-force scraper for HackerOne disclosed reports via their public API, collecting report IDs, links, titles, and states for security research and…

DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it

A fast and powerfull dashboard (admin) finder