Lists (14)
Sort Name ascending (A-Z)
Starred repositories
A list of interesting payloads, tips and tricks for bug bounty hunters.
best tool for finding SQLi,CRLF,XSS,LFi,OpenRedirect
The most powerful CRLF injection (HTTP Response Splitting) scanner.
Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
🧿 AutorizePro是一款强大越权检测 Burp 插件,通过增加 AI 辅助分析 && 进一步优化检测逻辑,大幅降低误报率,提升越权漏洞检出效率。 [ AutorizePro is a authorization enforcement detection extension for burp suite. By adding Ai-assisted analysis, it sign…
Internal penetration testing tool for Linux that can be used to enumerate OS information, domain information, shares, directories, and users through SMB.
A script designed to automatically discover new exploits and save results to a file or integrate with your Discord server. Also search for exploits related to specific CVEs of your choice.
🎈 Updated daily! A list of popular BitTorrent Trackers! / 每天更新!全网热门 BT Tracker 列表!
Advanced CORS Header Checker Tool with Vulnerability Detection and Bypass Attempts
Extract URLs, paths, secrets, and other interesting bits from JavaScript
SubSnipe is a tool designed to help find subdomains that are vulnerable to takeover.
Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner
GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep
使用 NextJS + Notion API 实现的,支持多种部署方案的静态博客,无需服务器、零门槛搭建网站,为Notion和所有创作者设计。 (A static blog built with NextJS and Notion API, supporting multiple deployment options. No server required, zero threshold t…
Check your WAF before an attacker does
某免费 PDF 转换站点 API 逆向,用于将 PPT 课件重排为无边距的 A4 幅面 PDF 文件用于在 iPad Pro 上批注(支持定制)。