-
onmouseover=alert(document.documentURI);
- onmouseover=alert(document.documentURI);
- onmouseover=alert(document.documentURI);
Stars
InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.
A curated list of various bug bounty tools
Script to test open Akamai ARL vulnerability.
Burpsuite Extension to bypass 403 restricted directory
SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 checklist
Making Favicon.ico based Recon Great again !
A script that monitors and extracts requested URLs and clients connected to the service by exploiting publicly accessible Apache server-status instances.
Extract endpoints from specific Git repository for fuzzing
ScanT3r - Module based Bug Bounty Automation Tool ( use Lotus instead github.com/bugBlocker/lotus )
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous …
A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me
A tool which scrapes public github repositories for common naming conventions in variables, folders and files
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl and Filter Urls With OpenRedirection or SSRF Parameters.
vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform a quick CMS security detection, information colle…
A collection of custom security tools for quick needs.
You can read the writeup on this script here
Converts a hostname (or URI) to IP address using your local resolver
TugaRecon is an advanced subdomain reconnaissance and intelligence framework built for security researchers, penetration testers and OSINT professionals. It combines OSINT enumeration, semantic ana…
Multiprocessing(Parallel)Subdomain Detect Script
Simple script to get your private/public or both programs using the Hackerone graphql.
Email recon made fast and easy, with a framework to build on