A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
Updated
Mar 12, 2022 - Python
{{ message }}
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
API, CLI, and Web App for analyzing and finding a person's profile in +1000 social media \ websites
A collection of hacking tools, resources and references to practice ethical hacking.
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
A list of resources for those interested in getting started in bug bounties
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
A curated list of awesome infosec courses and training resources.
Next generation web scanner
大型内网渗透扫描器&Cobalt Strike,Ladon8.9内置120个模块,包含信息收集/存活主机/端口扫描/服务识别/密码爆破/漏洞检测/漏洞利用。漏洞检测含MS17010/SMBGhost/Weblogic/ActiveMQ/Tomcat/Struts2,密码口令爆破(Mysql/Oracle/MSSQL)/FTP/SSH(Linux)/VNC/Windows(IPC/WMI/SMB/Netbios/LDAP/SmbHash/WmiHash/Winrm),远程执行命令(smbexec/wmiexe/psexec/atexec/sshexec/webshell),降权提权Runas、GetSystem,Poc/Exploit,支持Cobalt Strike 3.X-4.0
Git All the Payloads! A collection of web attack payloads.
Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.
Collection of the cheat sheets useful for pentesting
Phishing Tool & Information Collector
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
The ultimate WinRM shell for hacking/pentesting
Is your feature request related to a problem? Please describe.
Currently the tool supports a limited type of output formats. Generating a HTML report is one solution to very easily review the results generated.
Describe the solution you'd like
ffuf has a good working example of this. Anything that has some sort of DataTables on top, to be able to do sor
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
A list of commands, scripts, resources, and more that I have gathered and attempted to consolidate for use as OSCP (and more) study material. Commands in 'Usefulcommands' Keepnote. Bookmarks and reading material in 'BookmarkList' CherryTree. Reconscan Py2 and Py3. Custom ISO building.
XSS'OR - Hack with JavaScript.
Awesome Node.js Security resources
SSRF (Server Side Request Forgery) testing resources
Automatic SSRF fuzzer and exploitation tool
Penetration tests guide based on OWASP including test cases, resources and examples.
Add a description, image, and links to the pentest topic page so that developers can more easily learn about it.
To associate your repository with the pentest topic, visit your repo's landing page and select "manage topics."
I testing bruteforce my opencart store.
this is body request: