mirror of
https://github.com/hahwul/WebHackersWeapons.git
synced 2025-03-08 06:56:06 -05:00
Deploy README.md
This commit is contained in:
parent
3b50523872
commit
701b25075c
21
README.md
21
README.md
@ -5,7 +5,7 @@
|
||||
<br>
|
||||
<img src="https://img.shields.io/github/last-commit/hahwul/WebHackersWeapons?style=flat">
|
||||
<img src="https://img.shields.io/badge/PRs-welcome-cyan">
|
||||
<img src="https://github.com/hahwul/WebHackersWeapons/workflows/Build/badge.svg">
|
||||
<img src="https://github.com/hahwul/WebHackersWeapons/actions/workflows/deploy.yml/badge.svg">
|
||||
<a href="https://twitter.com/intent/follow?screen_name=hahwul"><img src="https://img.shields.io/twitter/follow/hahwul?style=flat&logo=twitter"></a>
|
||||
</h1>
|
||||
A collection of awesome tools used by Web hackers. Happy hacking , Happy bug-hunting
|
||||
@ -28,7 +28,7 @@ A collection of awesome tools used by Web hackers. Happy hacking , Happy bug-hun
|
||||
| | Attributes |
|
||||
|-------|---------------------------------------------------|
|
||||
| Types | `Army-Knife` `Recon` `Fuzzer` `Scanner` `Exploit` `Utils` `Etc`|
|
||||
| Tags | `proxy` `infra` `live-audit` `param` `subdomains` `apk` `dns` `domain` `jwt` `ssrf` `xss` `csp` `s3` `sqli` `403` `aaa` `ssl` `xxe` `url` `oast` `report` `wordlist` |
|
||||
| Tags | `proxy` `infra` `live-audit` `param` `endpoint` `subdomains` `apk` `dns` `domain` `jwt` `ssrf` `xss` `smuggle` `csp` `s3` `sqli` `403` `aaa` `ssl` `xxe` `url` `oast` `report` `wordlist` |
|
||||
| Langs | `Java` `Shell` `Go` `Rust` `C` `Python` `JavaScript` `Kotlin` `Ruby` `Perl` `TypeScript` `PHP` `BlitzBasic` `C#` `Typescript` `HTML` `C++` `Kotiln` `CSS` |
|
||||
|
||||
### Tools
|
||||
@ -150,7 +150,7 @@ A collection of awesome tools used by Web hackers. Happy hacking , Happy bug-hun
|
||||
|Scanner|[findom-xss](https://github.com/dwisiswant0/findom-xss)|A fast DOM based XSS vulnerability scanner with simplicity. ||`xss`||
|
||||
|Scanner|[sqlmap](https://github.com/sqlmapproject/sqlmap)|Automatic SQL injection and database takeover tool||||
|
||||
|Scanner|[ditto](https://github.com/evilsocket/ditto)|A tool for IDN homograph attacks and detection.||||
|
||||
|Scanner|[smuggler](https://github.com/defparam/smuggler)|Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3 ||||
|
||||
|Scanner|[smuggler](https://github.com/defparam/smuggler)|Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3 ||`smuggle`||
|
||||
|Scanner|[dalfox](https://github.com/hahwul/dalfox)|🌘🦊 DalFox(Finder Of XSS) / Parameter Analysis and XSS Scanning tool based on golang ||`xss`||
|
||||
|Scanner|[rapidscan](https://github.com/skavngr/rapidscan)|The Multi-Tool Web Vulnerability Scanner. ||||
|
||||
|Scanner|[gitleaks](https://github.com/zricethezav/gitleaks)|Scan git repos (or files) for secrets using regex and entropy 🔑||||
|
||||
@ -179,7 +179,7 @@ A collection of awesome tools used by Web hackers. Happy hacking , Happy bug-hun
|
||||
|Scanner|[OpenRedireX](https://github.com/devanshbatham/OpenRedireX)|A Fuzzer for OpenRedirect issues||||
|
||||
|Scanner|[CorsMe](https://github.com/Shivangx01b/CorsMe)|Cross Origin Resource Sharing MisConfiguration Scanner ||||
|
||||
|Scanner|[Chromium-based-XSS-Taint-Tracking](https://github.com/v8blink/Chromium-based-XSS-Taint-Tracking)|Cyclops is a web browser with XSS detection feature, it is chromium-based xss detection that used to find the flows from a source to a sink.||||
|
||||
|Scanner|[websocket-connection-smuggler](https://github.com/hahwul/websocket-connection-smuggler)|websocket-connection-smuggler||||
|
||||
|Scanner|[websocket-connection-smuggler](https://github.com/hahwul/websocket-connection-smuggler)|websocket-connection-smuggler||`smuggle`||
|
||||
|Scanner|[nmap](https://github.com/nmap/nmap)|Nmap - the Network Mapper. Github mirror of official SVN repository. ||||
|
||||
|Scanner|[http-request-smuggling](https://github.com/anshumanpattnaik/http-request-smuggling)|HTTP Request Smuggling Detection Tool||||
|
||||
|Scanner|[a2sv](https://github.com/hahwul/a2sv)|Auto Scanning to SSL Vulnerability ||`ssl`||
|
||||
@ -188,7 +188,7 @@ A collection of awesome tools used by Web hackers. Happy hacking , Happy bug-hun
|
||||
|Scanner|[ssrf-sheriff](https://github.com/teknogeek/ssrf-sheriff)|A simple SSRF-testing sheriff written in Go ||||
|
||||
|Scanner|[dontgo403](https://github.com/devploit/dontgo403)|Tool to bypass 40X response codes.||`403`||
|
||||
|Scanner|[jsprime](https://github.com/dpnishant/jsprime)|a javascript static security analysis tool||||
|
||||
|Scanner|[h2csmuggler](https://github.com/assetnote/h2csmuggler)|HTTP Request Smuggling Detection Tool||||
|
||||
|Scanner|[h2csmuggler](https://github.com/assetnote/h2csmuggler)|HTTP Request Smuggling Detection Tool||`smuggle`||
|
||||
|Scanner|[PPScan](https://github.com/msrkp/PPScan)|Client Side Prototype Pollution Scanner||||
|
||||
|Scanner|[xsinator.com](https://github.com/RUB-NDS/xsinator.com)|XS-Leak Browser Test Suite||||
|
||||
|Scanner|[wpscan](https://github.com/wpscanteam/wpscan)|WPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites. ||||
|
||||
@ -205,7 +205,7 @@ A collection of awesome tools used by Web hackers. Happy hacking , Happy bug-hun
|
||||
|Scanner|[gitGraber](https://github.com/hisxo/gitGraber)|gitGraber ||||
|
||||
|Scanner|[XSpear](https://github.com/hahwul/XSpear)|Powerfull XSS Scanning and Parameter analysis tool&gem ||`xss`||
|
||||
|Scanner|[nuclei](https://github.com/projectdiscovery/nuclei)|Nuclei is a fast tool for configurable targeted scanning based on templates offering massive extensibility and ease of use. ||||
|
||||
|Scanner|[ws-smuggler](https://github.com/hahwul/ws-smuggler)|WebSocket Connection Smuggler||||
|
||||
|Scanner|[ws-smuggler](https://github.com/hahwul/ws-smuggler)|WebSocket Connection Smuggler||`smuggle`||
|
||||
|Exploit|[Gopherus](https://github.com/tarunkant/Gopherus)|This tool generates gopher link for exploiting SSRF and gaining RCE in various servers ||||
|
||||
|Exploit|[SQL Ninja](https://gitlab.com/kalilinux/packages/sqlninja)|SQL Injection scanner||||
|
||||
|Exploit|[xxeserv](https://github.com/staaldraad/xxeserv)|A mini webserver with FTP support for XXE payloads||||
|
||||
@ -308,17 +308,18 @@ A collection of awesome tools used by Web hackers. Happy hacking , Happy bug-hun
|
||||
### Burpsuite and ZAP Addons
|
||||
| Type | Name | Description | Star | Tags | Badges |
|
||||
| --- | --- | --- | --- | --- | --- |
|
||||
|Recon|[attack-surface-detector-zap](https://github.com/secdec/attack-surface-detector-zap)|||||
|
||||
|Recon|[reflected-parameters](https://github.com/PortSwigger/reflected-parameters)|||||
|
||||
|Recon|[attack-surface-detector-zap](https://github.com/secdec/attack-surface-detector-zap)|The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters||`endpoint`||
|
||||
|Recon|[reflected-parameters](https://github.com/PortSwigger/reflected-parameters)|||`param`||
|
||||
|Recon|[attack-surface-detector-burp](https://github.com/secdec/attack-surface-detector-burp)|The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters||`endpoint`||
|
||||
|Recon|[HUNT](https://github.com/bugcrowd/HUNT)|Identifies common parameters vulnerable to certain vulnerability classes||`param`||
|
||||
|Recon|[BurpSuite-Secret_Finder](https://github.com/m4ll0k/BurpSuite-Secret_Finder)|||||
|
||||
|Recon|[burp-retire-js](https://github.com/h3xstream/burp-retire-js)|||||
|
||||
|Recon|[BurpJSLinkFinder](https://github.com/InitRoot/BurpJSLinkFinder)|||||
|
||||
|Fuzzer|[param-miner](https://github.com/PortSwigger/param-miner)|||`param`||
|
||||
|Scanner|[csp-auditor](https://github.com/GoSecure/csp-auditor)|||`csp`||
|
||||
|Scanner|[http-request-smuggler](https://github.com/PortSwigger/http-request-smuggler)|||||
|
||||
|Scanner|[http-request-smuggler](https://github.com/PortSwigger/http-request-smuggler)|||`smuggle`||
|
||||
|Scanner|[AuthMatrix](https://github.com/SecurityInnovation/AuthMatrix)|||`aaa`||
|
||||
|Scanner|[BurpSuiteHTTPSmuggler](https://github.com/nccgroup/BurpSuiteHTTPSmuggler)|||||
|
||||
|Scanner|[BurpSuiteHTTPSmuggler](https://github.com/nccgroup/BurpSuiteHTTPSmuggler)|||`smuggle`||
|
||||
|Scanner|[Autorize](https://github.com/Quitten/Autorize)|||`aaa`||
|
||||
|Scanner|[collaborator-everywhere](https://github.com/PortSwigger/collaborator-everywhere)|||||
|
||||
|Utils|[burp-piper](https://github.com/silentsignal/burp-piper)|||||
|
||||
|
@ -1 +1 @@
|
||||
Sun Aug 21 03:45:41 UTC 2022
|
||||
Sun Aug 21 03:52:16 UTC 2022
|
||||
|
Loading…
x
Reference in New Issue
Block a user