mirror of
https://github.com/hahwul/WebHackersWeapons.git
synced 2025-03-07 06:15:57 -05:00
update
This commit is contained in:
parent
f06c285915
commit
7e272191f1
26
README.md
26
README.md
@ -4,9 +4,14 @@
|
||||
<br>
|
||||
Web Hacker's Weapons
|
||||
<br>
|
||||
<a href="https://twitter.com/intent/follow?screen_name=hahwul"><img src="https://img.shields.io/twitter/follow/hahwul?style=flat-square"></a> <img src="https://img.shields.io/github/languages/top/hahwul/WebHackersWeapons?style=flat-square"> <img src="https://img.shields.io/github/last-commit/hahwul/WebHackersWeapons?style=flat-square">
|
||||
</h1>
|
||||
A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting
|
||||
|
||||
## Table of Contents
|
||||
- [Weapons](#weapons)
|
||||
- [Contribute](#contribute-and-contributor)
|
||||
|
||||
## Weapons
|
||||
| Type | Name | Description | Popularity | Language |
|
||||
| ---------- | :---------- | :----------: | :----------: | :----------: |
|
||||
@ -19,28 +24,48 @@ A collection of cool tools used by Web hackers. Happy hacking , Happy bug-huntin
|
||||
| Discovery/DOMAIN | [Amass](https://github.com/OWASP/Amass) | In-depth Attack Surface Mapping and Asset Discovery |  |  |
|
||||
| Discovery/DOMAIN | [assetfinder](https://github.com/tomnomnom/assetfinder) | Find domains and subdomains related to a given domain |  |  |
|
||||
| Discovery/DOMAIN | [findomain](https://github.com/Edu4rdSHL/findomain) | The fastest and cross-platform subdomain enumerator, do not waste your time. |  |  |
|
||||
| Discovery/DOMAIN | [knock](https://github.com/guelfoweb/knock) | Knock Subdomain Scan |  |  |
|
||||
| Discovery/DOMAIN | [subfinder](https://github.com/projectdiscovery/subfinder) | Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing. |  |  |
|
||||
| Discovery/FUZZ | [dirsearch](https://github.com/maurosoria/dirsearch) | Web path scanner |  |  |
|
||||
| Discovery/FUZZ | [gobuster](https://github.com/OJ/gobuster) | Directory/File, DNS and VHost busting tool written in Go |  |  |
|
||||
| Discovery/GIT | [GitMiner](https://github.com/UnkL4b/GitMiner) | Tool for advanced mining for content on Github |  |  |
|
||||
| Discovery/GIT | [gitGraber](https://github.com/hisxo/gitGraber) | gitGraber |  |  |
|
||||
| Discovery/GIT | [gitrob](https://github.com/michenriksen/gitrob) | Reconnaissance tool for GitHub organizations |  |  |
|
||||
| Discovery/HTTP | [Arjun](https://github.com/s0md3v/Arjun) | HTTP parameter discovery suite. |  |  |
|
||||
| Discovery/PORT | [masscan](https://github.com/robertdavidgraham/masscan) | TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes. |  |  |
|
||||
| Discovery/PORT | [naabu](https://github.com/projectdiscovery/naabu) | A fast port scanner written in go with focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests |  |  |
|
||||
| Discovery/PORT | [nmap](https://github.com/nmap/nmap) | Nmap - the Network Mapper. Github mirror of official SVN repository. |  |  |
|
||||
| Discovery/TKOV | [subjack](https://github.com/haccer/subjack) | Subdomain Takeover tool written in Go |  |  |
|
||||
| Discovery/URL | [waybackurls](https://github.com/tomnomnom/waybackurls) | Fetch all the URLs that the Wayback Machine knows about for a domain |  |  |
|
||||
| Discovery/VULN | [Silver](https://github.com/s0md3v/Silver) | Mass scan IPs for vulnerable services |  |  |
|
||||
| Fetch/TOM | [httprobe](https://github.com/tomnomnom/httprobe) | Take a list of domains and probe for working HTTP and HTTPS servers |  |  |
|
||||
| Fetch/TOM | [meg](https://github.com/tomnomnom/meg) | Fetch many paths for many hosts - without killing the hosts |  |  |
|
||||
| Fetch/WSOCK | [websocket-connection-smuggler](https://github.com/hahwul/websocket-connection-smuggler) | websocket-connection-smuggler |  |  |
|
||||
| Scanner/CORS | [Corsy](https://github.com/s0md3v/Corsy) | CORS Misconfiguration Scanner |  |  |
|
||||
| Scanner/FUZZ | [Medusa](https://github.com/pymedusa/Medusa) | Automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic. |  |  |
|
||||
| Scanner/FUZZ | [thc-hydra](https://github.com/vanhauser-thc/thc-hydra) | hydra |  |  |
|
||||
| Scanner/FUZZ | [wfuzz](https://github.com/xmendez/wfuzz) | Web application fuzzer |  |  |
|
||||
| Scanner/LFI | [LFISuite](https://github.com/D35m0nd142/LFISuite) | Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner |  |  |
|
||||
| Scanner/LFI | [dotdotpwn](https://github.com/wireghoul/dotdotpwn) | DotDotPwn - The Directory Traversal Fuzzer |  |  |
|
||||
| Scanner/NOSQL | [NoSQLMap](https://github.com/codingo/NoSQLMap) | Automated NoSQL database enumeration and web application exploitation tool. |  |  |
|
||||
| Scanner/SQL | [sqlmap](https://github.com/sqlmapproject/sqlmap) | Automatic SQL injection and database takeover tool |  |  |
|
||||
| Scanner/SQL | [sqlninja](https://github.com/xxgrunge/sqlninja) | SQL Injection Tool |  |  |
|
||||
| Scanner/SSL | [a2sv](https://github.com/hahwul/a2sv) | Auto Scanning to SSL Vulnerability |  |  |
|
||||
| Scanner/SSL | [testssl.sh](https://github.com/drwetter/testssl.sh) | Testing TLS/SSL encryption anywhere on any port |  |  |
|
||||
| Scanner/WP | [wpscan](https://github.com/wpscanteam/wpscan) | WPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites. |  |  |
|
||||
| Scanner/WVS | [Striker](https://github.com/s0md3v/Striker) | Striker is an offensive information and vulnerability scanner. |  |  |
|
||||
| Scanner/WVS | [arachni](https://github.com/Arachni/arachni) | Web Application Security Scanner Framework |  |  |
|
||||
| Scanner/WVS | [nikto](https://github.com/sullo/nikto) | Nikto web server scanner |  |  |
|
||||
| Scanner/WVS | [zap-cli](https://github.com/Grunny/zap-cli) | A simple tool for interacting with OWASP ZAP from the commandline. |  |  |
|
||||
| Scanner/XSS | [XSStrike](https://github.com/s0md3v/XSStrike) | Most advanced XSS scanner. |  |  |
|
||||
| Scanner/XSS | [xspear](https://github.com/hahwul/xspear) | Powerfull XSS Scanning and Parameter analysis tool&gem |  |  |
|
||||
| Utility/CLIP | [ftc](https://github.com/hahwul/ftc) | simple copy to file to clipboard |  |  |
|
||||
| Utility/FIND | [fzf](https://github.com/junegunn/fzf) | A command-line fuzzy finder |  |  |
|
||||
| Utility/GREP | [gf](https://github.com/tomnomnom/gf) | A wrapper around grep, to help you grep for things |  |  |
|
||||
| Utility/JSON | [gron](https://github.com/tomnomnom/gron) | Make JSON greppable! |  |  |
|
||||
| Utility/S3 | [s3reverse](https://github.com/hahwul/s3reverse) | The format of various s3 buckets is convert in one format. for bugbounty and security testing. |  |  |
|
||||
| Utility/VULN | [oxml_xxe](https://github.com/BuffaloWill/oxml_xxe) | A tool for embedding XXE/XML exploits into different filetypes |  |  |
|
||||
| Utility/VULN | [ysoserial](https://github.com/frohoff/ysoserial) | A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization. |  |  |
|
||||
## Contribute and Contributor
|
||||
### Usage of add-tool
|
||||
```
|
||||
@ -78,4 +103,3 @@ Successfully Opened data.json
|
||||
$ ./distribute-readme
|
||||
=> show new README file
|
||||
```
|
||||
|
||||
|
@ -75,7 +75,7 @@ func writeJSON(category string, name string, method string, data string) {
|
||||
}
|
||||
|
||||
func main() {
|
||||
repourl := flag.String("url", "", "github / gitlab / bitbucket url")
|
||||
repourl := flag.String("url", "", "any url")
|
||||
first := flag.Bool("isFirst", false, "if you add new type, it use")
|
||||
flag.Parse()
|
||||
if flag.NFlag() == 0 {
|
||||
|
104
data.json
104
data.json
@ -19,6 +19,21 @@
|
||||
"Method": "CORS",
|
||||
"Type": "Scanner"
|
||||
},
|
||||
"GitMiner": {
|
||||
"Data": "| Discovery/GIT | [GitMiner](https://github.com/UnkL4b/GitMiner) | Tool for advanced mining for content on Github |  |  |",
|
||||
"Method": "GIT",
|
||||
"Type": "Discovery"
|
||||
},
|
||||
"LFISuite": {
|
||||
"Data": "| Scanner/LFI | [LFISuite](https://github.com/D35m0nd142/LFISuite) | Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner |  |  |",
|
||||
"Method": "LFI",
|
||||
"Type": "Scanner"
|
||||
},
|
||||
"Medusa": {
|
||||
"Data": "| Scanner/FUZZ | [Medusa](https://github.com/pymedusa/Medusa) | Automatic Video Library Manager for TV Shows. It watches for new episodes of your favorite shows, and when they are posted it does its magic. |  |  |",
|
||||
"Method": "FUZZ",
|
||||
"Type": "Scanner"
|
||||
},
|
||||
"NoSQLMap": {
|
||||
"Data": "| Scanner/NOSQL | [NoSQLMap](https://github.com/codingo/NoSQLMap) | Automated NoSQL database enumeration and web application exploitation tool. |  |  |",
|
||||
"Method": "NOSQL",
|
||||
@ -49,16 +64,31 @@
|
||||
"Method": "SSL",
|
||||
"Type": "Scanner"
|
||||
},
|
||||
"arachni": {
|
||||
"Data": "| Scanner/WVS | [arachni](https://github.com/Arachni/arachni) | Web Application Security Scanner Framework |  |  |",
|
||||
"Method": "WVS",
|
||||
"Type": "Scanner"
|
||||
},
|
||||
"assetfinder": {
|
||||
"Data": "| Discovery/DOMAIN | [assetfinder](https://github.com/tomnomnom/assetfinder) | Find domains and subdomains related to a given domain |  |  |",
|
||||
"Method": "DOMAIN",
|
||||
"Type": "Discovery"
|
||||
},
|
||||
"dirsearch": {
|
||||
"Data": "| Discovery/FUZZ | [dirsearch](https://github.com/maurosoria/dirsearch) | Web path scanner |  |  |",
|
||||
"Method": "FUZZ",
|
||||
"Type": "Discovery"
|
||||
},
|
||||
"dnsprobe": {
|
||||
"Data": "| Discovery/DNS | [dnsprobe](https://github.com/projectdiscovery/dnsprobe) | DNSProb (beta) is a tool built on top of retryabledns that allows you to perform multiple dns queries of your choice with a list of user supplied resolvers. |  |  |",
|
||||
"Method": "DNS",
|
||||
"Type": "Discovery"
|
||||
},
|
||||
"dotdotpwn": {
|
||||
"Data": "| Scanner/LFI | [dotdotpwn](https://github.com/wireghoul/dotdotpwn) | DotDotPwn - The Directory Traversal Fuzzer |  |  |",
|
||||
"Method": "LFI",
|
||||
"Type": "Scanner"
|
||||
},
|
||||
"findomain": {
|
||||
"Data": "| Discovery/DOMAIN | [findomain](https://github.com/Edu4rdSHL/findomain) | The fastest and cross-platform subdomain enumerator, do not waste your time. |  |  |",
|
||||
"Method": "DOMAIN",
|
||||
@ -69,11 +99,31 @@
|
||||
"Method": "CLIP",
|
||||
"Type": "Utility"
|
||||
},
|
||||
"fzf": {
|
||||
"Data": "| Utility/FIND | [fzf](https://github.com/junegunn/fzf) | A command-line fuzzy finder |  |  |",
|
||||
"Method": "FIND",
|
||||
"Type": "Utility"
|
||||
},
|
||||
"gf": {
|
||||
"Data": "| Utility/GREP | [gf](https://github.com/tomnomnom/gf) | A wrapper around grep, to help you grep for things |  |  |",
|
||||
"Method": "GREP",
|
||||
"Type": "Utility"
|
||||
},
|
||||
"gitGraber": {
|
||||
"Data": "| Discovery/GIT | [gitGraber](https://github.com/hisxo/gitGraber) | gitGraber |  |  |",
|
||||
"Method": "GIT",
|
||||
"Type": "Discovery"
|
||||
},
|
||||
"gitrob": {
|
||||
"Data": "| Discovery/GIT | [gitrob](https://github.com/michenriksen/gitrob) | Reconnaissance tool for GitHub organizations |  |  |",
|
||||
"Method": "GIT",
|
||||
"Type": "Discovery"
|
||||
},
|
||||
"gobuster": {
|
||||
"Data": "| Discovery/FUZZ | [gobuster](https://github.com/OJ/gobuster) | Directory/File, DNS and VHost busting tool written in Go |  |  |",
|
||||
"Method": "FUZZ",
|
||||
"Type": "Discovery"
|
||||
},
|
||||
"gospider": {
|
||||
"Data": "| Discovery/CRAWL | [gospider](https://github.com/jaeles-project/gospider) | Gospider - Fast web spider written in Go |  |  |",
|
||||
"Method": "CRAWL",
|
||||
@ -89,6 +139,11 @@
|
||||
"Method": "TOM",
|
||||
"Type": "Fetch"
|
||||
},
|
||||
"knock": {
|
||||
"Data": "| Discovery/DOMAIN | [knock](https://github.com/guelfoweb/knock) | Knock Subdomain Scan |  |  |",
|
||||
"Method": "DOMAIN",
|
||||
"Type": "Discovery"
|
||||
},
|
||||
"masscan": {
|
||||
"Data": "| Discovery/PORT | [masscan](https://github.com/robertdavidgraham/masscan) | TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes. |  |  |",
|
||||
"Method": "PORT",
|
||||
@ -104,11 +159,21 @@
|
||||
"Method": "PORT",
|
||||
"Type": "Discovery"
|
||||
},
|
||||
"nikto": {
|
||||
"Type": "Scanner",
|
||||
"Data": "| Scanner/WVS | [nikto](https://github.com/sullo/nikto) | Nikto web server scanner |  |  |",
|
||||
"Method": "WVS"
|
||||
},
|
||||
"nmap": {
|
||||
"Data": "| Discovery/PORT | [nmap](https://github.com/nmap/nmap) | Nmap - the Network Mapper. Github mirror of official SVN repository. |  |  |",
|
||||
"Method": "PORT",
|
||||
"Type": "Discovery"
|
||||
},
|
||||
"oxml_xxe": {
|
||||
"Data": "| Utility/VULN | [oxml_xxe](https://github.com/BuffaloWill/oxml_xxe) | A tool for embedding XXE/XML exploits into different filetypes |  |  |",
|
||||
"Method": "VULN",
|
||||
"Type": "Utility"
|
||||
},
|
||||
"s3reverse": {
|
||||
"Data": "| Utility/S3 | [s3reverse](https://github.com/hahwul/s3reverse) | The format of various s3 buckets is convert in one format. for bugbounty and security testing. |  |  |",
|
||||
"Method": "S3",
|
||||
@ -134,6 +199,21 @@
|
||||
"Method": "DOMAIN",
|
||||
"Type": "Discovery"
|
||||
},
|
||||
"subjack": {
|
||||
"Data": "| Discovery/TKOV | [subjack](https://github.com/haccer/subjack) | Subdomain Takeover tool written in Go |  |  |",
|
||||
"Method": "TKOV",
|
||||
"Type": "Discovery"
|
||||
},
|
||||
"testssl.sh": {
|
||||
"Data": "| Scanner/SSL | [testssl.sh](https://github.com/drwetter/testssl.sh) | Testing TLS/SSL encryption anywhere on any port |  |  |",
|
||||
"Method": "SSL",
|
||||
"Type": "Scanner"
|
||||
},
|
||||
"thc-hydra": {
|
||||
"Data": "| Scanner/FUZZ | [thc-hydra](https://github.com/vanhauser-thc/thc-hydra) | hydra |  |  |",
|
||||
"Method": "FUZZ",
|
||||
"Type": "Scanner"
|
||||
},
|
||||
"waybackurls": {
|
||||
"Data": "| Discovery/URL | [waybackurls](https://github.com/tomnomnom/waybackurls) | Fetch all the URLs that the Wayback Machine knows about for a domain |  |  |",
|
||||
"Method": "URL",
|
||||
@ -144,14 +224,34 @@
|
||||
"Method": "WSOCK",
|
||||
"Type": "Fetch"
|
||||
},
|
||||
"wfuzz": {
|
||||
"Data": "| Scanner/FUZZ | [wfuzz](https://github.com/xmendez/wfuzz) | Web application fuzzer |  |  |",
|
||||
"Method": "FUZZ",
|
||||
"Type": "Scanner"
|
||||
},
|
||||
"wpscan": {
|
||||
"Data": "| Scanner/WP | [wpscan](https://github.com/wpscanteam/wpscan) | WPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites. |  |  |",
|
||||
"Method": "WP",
|
||||
"Type": "Scanner"
|
||||
},
|
||||
"xspear": {
|
||||
"Data": "| Scanner/XSS | [xspear](https://github.com/hahwul/xspear) | Powerfull XSS Scanning and Parameter analysis tool\u0026gem |  |  |",
|
||||
"Method": "XSS",
|
||||
"Type": "Scanner"
|
||||
},
|
||||
"ysoserial": {
|
||||
"Data": "| Utility/VULN | [ysoserial](https://github.com/frohoff/ysoserial) | A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization. |  |  |",
|
||||
"Method": "VULN",
|
||||
"Type": "Utility"
|
||||
},
|
||||
"zap-cli": {
|
||||
"Data": "| Scanner/WVS | [zap-cli](https://github.com/Grunny/zap-cli) | A simple tool for interacting with OWASP ZAP from the commandline. |  |  |",
|
||||
"Method": "WVS",
|
||||
"Type": "Scanner"
|
||||
},
|
||||
"zaproxy": {
|
||||
"Type": "Army-Knife",
|
||||
"Data": "| Army-Knife/ZAP | [zaproxy](https://github.com/zaproxy/zaproxy) | The OWASP ZAP core project |  |  |",
|
||||
"Method": "ZAP"
|
||||
"Method": "ZAP",
|
||||
"Type": "Army-Knife"
|
||||
}
|
||||
}
|
Binary file not shown.
Loading…
x
Reference in New Issue
Block a user