WordPress 4.8.2 SQLi vulnerability
On 31th Oct, WordPress 4.8.3 has been released. This is a security release for all previous versions and we strongly encourage you to update your sites immediately. Details WordPress versions 4.8.2 and earlier...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published November 1, 2017 · Last modified January 3, 2018
On 31th Oct, WordPress 4.8.3 has been released. This is a security release for all previous versions and we strongly encourage you to update your sites immediately. Details WordPress versions 4.8.2 and earlier...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published October 30, 2017 · Last modified May 1, 2024
Blazy Blazy is a modern login page bruteforcer. Features Easy target selections Smart form and error detection CSRF and Clickjacking Scanner Cloudflare and WAF Detector 90% accurate results Checks for...
Cross-Site “Scripter” (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities. It provides several options to try to bypass certain filters and various special techniques for...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published October 24, 2017 · Last modified November 8, 2017
reddalert AWS security monitoring/alerting tool built on top of Netflix’s EDDA project. What do we want to see? Examples: security group whitelists some weird port(range) ELB forwards traffic to some weird port...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published October 22, 2017 · Last modified May 1, 2024
redirect.py open redirect subdomains scanner by ak1t4 know.0nix@gmail.com Download git clone https://github.com/ak1t4/open-redirect-scanner.git Use ./redirect.py [subdomains.file] [redirect-payload] Example ./redirect.py uber.list ‘//yahoo.com/%2F..’ Payloads examples: #payload = ‘//www.google.com/%2F..’ #payload2 = ‘//www.yahoo.com//‘ #payload3 = ‘//www.yahoo.com//%2F%2E%2E’ Enjoy!...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published October 21, 2017 · Last modified November 4, 2024
Security Monkey Security Monkey monitors your AWS and GCP accounts for policy changes and alerts on insecure configurations. It provides a single UI to browse and search through all of your...
Programming / Web Vulnerability Analysis
by do son · Published October 18, 2017 · Last modified November 4, 2024
PHP Secure Configuration Checker Check current PHP configuration for potential security flaws. Simply access this file from your web server or run on CLI. Author This software was written by...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published October 8, 2017 · Last modified November 5, 2017
reflector Description Burp Suite extension is able to find reflected XSS on the page in real-time while browsing on the website and include some features as: Highlighting of reflection in...
Web Exploitation / Web Vulnerability Analysis / WebApp PenTest
by do son · Published October 6, 2017 · Last modified November 4, 2024
NoSQLMap NoSQLMap is an open source Python tool designed to audit for as well as automate injection attacks and exploit default configuration weaknesses in NoSQL databases and web applications using...
CORStest A simple CORS misconfiguration scanner Based on the research of James Kettle CORStest is a quick & dirty Python 2 tool to find Cross-Origin Resource Sharing (CORS) misconfigurations. It takes a text...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published October 2, 2017 · Last modified November 4, 2024
UpPwn UpPwn is a script that automates detection of security flaws on websites’ file upload systems. In some cases, it also allows exploiting these vulnerabilities in order to upload malicious...
Web Information Gathering / Web Vulnerability Analysis / WebApp PenTest
by do son · Published September 29, 2017 · Last modified November 4, 2024
WebXploiter The main purpose of this tool is to help to automate the manual Recon techniques + basic exploitation techniques which we used to try each time when we are...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published September 29, 2017 · Last modified November 5, 2017
mando.me: Web Command Injection Tool PHP Command Injection exploitation tool Exploit web page and upload simple-shell.php (or simply find an existing exploitable command injection). Execute the controller to exploit the...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published September 28, 2017 · Last modified November 4, 2024
Installing OpenVAS 9 on Ubuntu If you install OpenVAS in an Ubuntu virtual machine, I recommend adding as many CPUs as possible to speed up the scan. The recommended minimum...
Angular Client-Side Template Injection Scanner ACSTIS helps you to scan certain web applications for AngularJS Client-Side Template Injection (sometimes referred to as CSTI, sandbox escape or sandbox bypass). It supports...