Stars
AI-powered assistant that integrates seamlessly with Caido
A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me
Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR / APK applications.
klsecservices / BFScan
Forked from BlackFan/BFScanTool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR / APK applications.
Creats a strings.xml file by Google auto-translating an input strings.xml file
SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list
Prototype Pollution using `flat` with Next.js
Issues with WebSocket reverse proxying allowing to smuggle HTTP requests
GHIDRA plugin to parse, disassemble and decompile NodeJS Bytenode (JSC) binaries
This repository contains all the XSS cheatsheet data to allow contributions from the community.
The cheat sheet about Java Deserialization vulnerabilities
Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
Burp extension to passively scan for applications revealing software version numbers
Burp Suite plugin for binary search on HTTP parameters