Lists (24)
Sort Name ascending (A-Z)
android pentest
api pentesting
burpsuite utilized
Bypass (4xx)
checklists, methodologies
code review, devsecops
general stuffs
ios pentest
node stuffs
payloads
pentest note taking apps
recon (application)
recon (assets)
recon (dorks, queries)
recon (javascripts)
vulnerable android apps
vulnerable ios apps
vulnerable [web] apps
vulns (open redirect)
vulns (sqli)
vulns (ssrf)
vulns (xss)
wlists
writeups & edu
Stars
A tool for reverse engineering Android apk files
Tools to work with android .dex and java .class files
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
An xposed module that disables SSL certificate checking for the purposes of auditing an app with cert pinning
HaE - Highlighter and Extractor, Empower ethical hacker for efficient operations.
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
A cli tool that helps signing and zip aligning single or multiple Android application packages (APKs) with either debug or provided release certificates. It supports v1, v2 and v3 Android signing s…
A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅
The new bridge between Burp Suite and Frida!
Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules thro…
BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件
Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities
Vulnerable app with examples showing how to not use secrets
Nuclei plugin for BurpSuite
Burpsuite - Route Vulnerable Scanning 递归式被动检测脆弱路径的burp插件
Burp plugin able to find reflected XSS on page in real-time while browsing on site
HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite
sqlmap4burp++是一款兼容Windows,mac,linux多个系统平台的Burp与sqlmap联动插件
Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.
Android API restriction bypass for all Android Versions
The Web Application Hacker's Handbook - Extra Content