mirror of
https://github.com/hahwul/WebHackersWeapons.git
synced 2025-02-23 00:19:50 -05:00
distribute readme
This commit is contained in:
parent
c14ceae1ef
commit
eff2b547f8
@ -144,7 +144,10 @@ A collection of cool tools used by Web hackers. Happy hacking , Happy bug-huntin
|
||||
| Scanner/RECON | [megplus](https://github.com/EdOverflow/megplus) | Automated reconnaissance wrapper — TomNomNom's meg on steroids. [DEPRECATED] | data:image/s3,"s3://crabby-images/d5a64/d5a64cf50f4e2108189fc2235057beaec3fdfaf4" alt="" | data:image/s3,"s3://crabby-images/665c2/665c2db11fc8cc449641b5136a4460cd2921b2ab" alt="" |
|
||||
| Scanner/S3 | [AWSBucketDump](https://github.com/jordanpotti/AWSBucketDump) | Security Tool to Look For Interesting Files in S3 Buckets | data:image/s3,"s3://crabby-images/80dfa/80dfa8c2f9560e8eee18213673d8f70b3a0f9fd5" alt="" | data:image/s3,"s3://crabby-images/0de59/0de59b1e1787cb37aebe34247bcf507a803f0edc" alt="" |
|
||||
| Scanner/S3 | [S3Scanner](https://github.com/sa7mon/S3Scanner) | Scan for open AWS S3 buckets and dump the contents | data:image/s3,"s3://crabby-images/bf543/bf543569ee5fd76ccff7d72b9dfdacc9943bc93d" alt="" | data:image/s3,"s3://crabby-images/62c49/62c49e8d797ff5060ad3cbb9c56723f8a55e7b9e" alt="" |
|
||||
| Scanner/SMUGGLE | [HRS](https://github.com/SafeBreach-Labs/HRS) | HTTP Request Smuggling demonstration Perl script, for variants 1, 2 and 5 in my BlackHat US 2020 paper HTTP Request Smuggling in 2020. | data:image/s3,"s3://crabby-images/795cc/795cc149e7f86345b0ff70ce9a1a49273fdef8ce" alt="" | data:image/s3,"s3://crabby-images/1d60a/1d60a9bd66f78914f48aef4c731d0efaa2969309" alt="" |
|
||||
| Scanner/SMUGGLE | [h2csmuggler](https://github.com/BishopFox/h2csmuggler) | HTTP Request Smuggling over HTTP/2 Cleartext (h2c) | data:image/s3,"s3://crabby-images/f407e/f407e5006518580cb9eaed8efaa910819d82aa2f" alt="" | data:image/s3,"s3://crabby-images/36b8c/36b8c3f9e131e5354c763cd18ba650d41b0a81b4" alt="" |
|
||||
| Scanner/SMUGGLE | [http-request-smuggler](https://github.com/PortSwigger/http-request-smuggler) | This extension should not be confused with Burp Suite HTTP Smuggler, which uses similar techniques but is focused exclusively bypassing WAFs. | data:image/s3,"s3://crabby-images/20baf/20baf9649e1615fb724917243d87fdf6da6a477d" alt="" | data:image/s3,"s3://crabby-images/d964b/d964b21cdfb0ea5ede38a4c1d1cb3b2c057837e6" alt="" |
|
||||
| Scanner/SMUGGLE | [http-request-smuggling](https://github.com/anshumanpattnaik/http-request-smuggling) | HTTP Request Smuggling Detection Tool | data:image/s3,"s3://crabby-images/7657d/7657d011759294b247a077846daade3e4bb6820f" alt="" | data:image/s3,"s3://crabby-images/e08f5/e08f59240b2c29bb445f27d5b41ab2acc7673503" alt="" |
|
||||
| Scanner/SMUGGLE | [http2smugl](https://github.com/neex/http2smugl) | This tool helps to detect and exploit HTTP request smuggling in cases it can be achieved via HTTP/2 -> HTTP/1.1 conversion by the frontend server. | data:image/s3,"s3://crabby-images/0c9ab/0c9ab20396b12e074f7f99877dc217a660279ef5" alt="" | data:image/s3,"s3://crabby-images/79296/79296ee92967553702659b5bba7534db0f0ab109" alt="" |
|
||||
| Scanner/SMUGGLE | [smuggler](https://github.com/defparam/smuggler) | Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3 | data:image/s3,"s3://crabby-images/b9374/b9374b584eebb9556bb5d024f6e40dfd009eb5c3" alt="" | data:image/s3,"s3://crabby-images/2727e/2727e4ca38271d3b1a29de100adb166361a2435a" alt="" |
|
||||
| Scanner/SMUGGLE | [websocket-connection-smuggler](https://github.com/hahwul/websocket-connection-smuggler) | websocket-connection-smuggler | data:image/s3,"s3://crabby-images/da14a/da14a963fb3d855ac201ceaf5e70a40d1f199fc2" alt="" | data:image/s3,"s3://crabby-images/0353e/0353e36fce21af8d82a20354043ee2ac5a3860d5" alt="" |
|
||||
|
54
data.json
54
data.json
@ -431,6 +431,22 @@
|
||||
"Windows": "cd GraphQLmap; git pull -v ; pip install -r requirements.txt"
|
||||
}
|
||||
},
|
||||
"HRS": {
|
||||
"Type": "Scanner",
|
||||
"Data": "| Scanner/SMUGGLE | [HRS](https://github.com/SafeBreach-Labs/HRS) | HTTP Request Smuggling demonstration Perl script, for variants 1, 2 and 5 in my BlackHat US 2020 paper HTTP Request Smuggling in 2020. | data:image/s3,"s3://crabby-images/795cc/795cc149e7f86345b0ff70ce9a1a49273fdef8ce" alt="" | data:image/s3,"s3://crabby-images/1d60a/1d60a9bd66f78914f48aef4c731d0efaa2969309" alt="" |",
|
||||
"Method": "SMUGGLE",
|
||||
"Description": "HTTP Request Smuggling demonstration Perl script, for variants 1, 2 and 5 in my BlackHat US 2020 paper HTTP Request Smuggling in 2020.",
|
||||
"Install": {
|
||||
"Linux": "",
|
||||
"MacOS": "",
|
||||
"Windows": ""
|
||||
},
|
||||
"Update": {
|
||||
"Linux": "",
|
||||
"MacOS": "",
|
||||
"Windows": ""
|
||||
}
|
||||
},
|
||||
"HydraRecon": {
|
||||
"Data": "| Discovery/ALL | [HydraRecon](https://github.com/aufzayed/HydraRecon) | All In One, Fast, Easy Recon Tool | data:image/s3,"s3://crabby-images/869f4/869f462f21a1058dad73629a91001be3ed0032e7" alt="" | data:image/s3,"s3://crabby-images/73fd5/73fd52a8fd2f581872a21c2f85722eb86fbfa1a2" alt="" |",
|
||||
"Description": "All In One, Fast, Easy Recon Tool",
|
||||
@ -2079,16 +2095,48 @@
|
||||
"Windows": "go get github.com/htcat/htcat/cmd/htcat"
|
||||
}
|
||||
},
|
||||
"http2smugl": {
|
||||
"Type": "Scanner",
|
||||
"Data": "| Scanner/SMUGGLE | [http2smugl](https://github.com/neex/http2smugl) | This tool helps to detect and exploit HTTP request smuggling in cases it can be achieved via HTTP/2 -\u003e HTTP/1.1 conversion by the frontend server. | data:image/s3,"s3://crabby-images/0c9ab/0c9ab20396b12e074f7f99877dc217a660279ef5" alt="" | data:image/s3,"s3://crabby-images/79296/79296ee92967553702659b5bba7534db0f0ab109" alt="" |",
|
||||
"http-request-smuggler": {
|
||||
"Data": "| Scanner/SMUGGLE | [http-request-smuggler](https://github.com/PortSwigger/http-request-smuggler) | This extension should not be confused with Burp Suite HTTP Smuggler, which uses similar techniques but is focused exclusively bypassing WAFs. | data:image/s3,"s3://crabby-images/20baf/20baf9649e1615fb724917243d87fdf6da6a477d" alt="" | data:image/s3,"s3://crabby-images/d964b/d964b21cdfb0ea5ede38a4c1d1cb3b2c057837e6" alt="" |",
|
||||
"Description": "This extension should not be confused with Burp Suite HTTP Smuggler, which uses similar techniques but is focused exclusively bypassing WAFs.",
|
||||
"Install": {
|
||||
"Linux": "",
|
||||
"MacOS": "",
|
||||
"Windows": ""
|
||||
},
|
||||
"Method": "SMUGGLE",
|
||||
"Type": "Scanner",
|
||||
"Update": {
|
||||
"Linux": "",
|
||||
"MacOS": "",
|
||||
"Windows": ""
|
||||
}
|
||||
},
|
||||
"http-request-smuggling": {
|
||||
"Data": "| Scanner/SMUGGLE | [http-request-smuggling](https://github.com/anshumanpattnaik/http-request-smuggling) | HTTP Request Smuggling Detection Tool | data:image/s3,"s3://crabby-images/7657d/7657d011759294b247a077846daade3e4bb6820f" alt="" | data:image/s3,"s3://crabby-images/e08f5/e08f59240b2c29bb445f27d5b41ab2acc7673503" alt="" |",
|
||||
"Description": "HTTP Request Smuggling Detection Tool",
|
||||
"Install": {
|
||||
"Linux": "",
|
||||
"MacOS": "",
|
||||
"Windows": ""
|
||||
},
|
||||
"Method": "SMUGGLE",
|
||||
"Type": "Scanner",
|
||||
"Update": {
|
||||
"Linux": "",
|
||||
"MacOS": "",
|
||||
"Windows": ""
|
||||
}
|
||||
},
|
||||
"http2smugl": {
|
||||
"Data": "| Scanner/SMUGGLE | [http2smugl](https://github.com/neex/http2smugl) | This tool helps to detect and exploit HTTP request smuggling in cases it can be achieved via HTTP/2 -\u003e HTTP/1.1 conversion by the frontend server. | data:image/s3,"s3://crabby-images/0c9ab/0c9ab20396b12e074f7f99877dc217a660279ef5" alt="" | data:image/s3,"s3://crabby-images/79296/79296ee92967553702659b5bba7534db0f0ab109" alt="" |",
|
||||
"Description": "This tool helps to detect and exploit HTTP request smuggling in cases it can be achieved via HTTP/2 -\u003e HTTP/1.1 conversion by the frontend server.",
|
||||
"Install": {
|
||||
"Linux": "",
|
||||
"MacOS": "",
|
||||
"Windows": ""
|
||||
},
|
||||
"Method": "SMUGGLE",
|
||||
"Type": "Scanner",
|
||||
"Update": {
|
||||
"Linux": "",
|
||||
"MacOS": "",
|
||||
|
Loading…
x
Reference in New Issue
Block a user