A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
Updated
Jul 19, 2021 - Python
{{ message }}
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
API, CLI & Web App for analyzing & finding a person's profile across social media \ websites (Detections are updated regularly)
A list of resources for those interested in getting started in bug bounties
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
A curated list of awesome infosec courses and training resources.
Next generation web scanner
Git All the Payloads! A collection of web attack payloads.
Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.
大型内网渗透扫描器&Cobalt Strike,Ladon7.2内置94个模块,包含信息收集/存活主机/端口扫描/服务识别/密码爆破/漏洞检测/漏洞利用。漏洞检测含MS17010/SMBGhost/Weblogic/ActiveMQ/Tomcat/Struts2,密码口令爆破(Mysql/Oracle/MSSQL)/FTP/SSH(Linux)/VNC/Windows(IPC/WMI/SMB/Netbios/LDAP/SmbHash/WmiHash/Winrm),远程执行命令(wmiexe/psexec/atexec/sshexec/webshell),降权提权Runas、GetSystem,Poc/Exploit,支持Cobalt Strike 3.X-4.0
Collection of the cheat sheets useful for pentesting
so if the password is correct it accepts it .... and if it's wrong it says the entered password is wrong .. and asks for the password again .. just like what the real sites do :)
XSS'OR - Hack with JavaScript.
The ultimate WinRM shell for hacking/pentesting
A list of commands, scripts, resources, and more that I have gathered and attempted to consolidate for use as OSCP (and more) study material. Commands in 'Usefulcommands' Keepnote. Bookmarks and reading material in 'BookmarkList' CherryTree. Reconscan Py2 and Py3. Custom ISO building.
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password
Is your feature request related to a problem? Please describe.
Currently the tool supports a limited type of output formats. Generating a HTML report is one solution to very easily review the results generated.
Describe the solution you'd like
ffuf has a good working example of this. Anything that has some sort of DataTables on top, to be able to do sor
SSRF (Server Side Request Forgery) testing resources
Awesome Node.js Security resources
Penetration tests guide based on OWASP including test cases, resources and examples.
Collection of quality safety articles. Awesome articles.
Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.org https://twitter.com/owtfp
Automatic SSRF fuzzer and exploitation tool
溯光 (TrackRay) 3 beta
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
Add a description, image, and links to the pentest topic page so that developers can more easily learn about it.
To associate your repository with the pentest topic, visit your repo's landing page and select "manage topics."
I testing bruteforce my opencart store.
this is body request: