PenBox: A Penetration Testing Framework
PenBox – A Penetration Testing Framework A Penetration Testing Framework, The Hacker’s Repo our hope is in the last version we will have the very script that a hacker needs...
Network PenTest / Password Attacks / Sniffing & Spoofing / Web Exploitation / Web Information Gathering / Web Vulnerability Analysis / WebApp PenTest / Wireless
by do son · Published September 27, 2017 · Last modified May 18, 2018
PenBox – A Penetration Testing Framework A Penetration Testing Framework, The Hacker’s Repo our hope is in the last version we will have the very script that a hacker needs...
AWS Extender AWS Extender is a BurpSuite extension to identify and test S3 buckets as well as Google Storage buckets and Azure Storage containers for common misconfiguration issues using the boto/boto3 SDK...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published September 18, 2017 · Last modified November 4, 2024
XML Entity Injection (XXE) An XML External Entity attack is a type of attack against an application that parses XML input. This attack occurs when XML input containing a reference to an external...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published September 16, 2017 · Last modified November 4, 2024
Jaidam is an open source penetration testing tool that would take as input a list of domain names, scan them, determine if WordPress or Joomla platform was used and finally...
Blindy Simple script for running brute-force blind MySql injection Note: this script was created for fun, helpful in some ctf challenges 🙂 Description The script will run through queries listed...
Web Exploitation / Web Information Gathering / Web Vulnerability Analysis / WebApp PenTest
by do son · Published September 15, 2017 · Last modified May 1, 2024
What’s GoLismero? GoLismero is an open source framework for security testing. It’s currently geared towards web security, but it can easily be expanded to other kinds of scans. The most...
Web Information Gathering / Web Vulnerability Analysis / WebApp PenTest
by do son · Published September 15, 2017 · Last modified November 4, 2024
EllaScanner Passive web scanner. EllaScanner is a simple passive web scanner. Using this tool you can simply check your site’s security state. Scanning of the site consists several phases: At...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published September 12, 2017 · Last modified November 4, 2024
CRLF.py CRLF – Auto CRLF Injector Author: Rudra Sarkar Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published September 11, 2017 · Last modified November 4, 2024
nycto-dork dork scanner with Sqli and Lfi testing Download Usage Source: https://github.com/nycto-hackerone/nycto-dork
Information Gathering / Network PenTest / Vulnerability Analysis / Web Information Gathering / Web Vulnerability Analysis / WebApp PenTest
by do son · Published September 9, 2017
NMapGUI is an advanced graphical user interface for NMap network analysis tool. It allows to extend and ease the typical usage of NMap by providen a visual and fast interface...
Taint php extension used to detect XSS codes(tainted string), And also can be used to spot sql injection vulnerabilities, shell inject, etc. The idea is from https://wiki.php.net/rfc/taint, I implemented it in...
Web Information Gathering / Web Vulnerability Analysis / WebApp PenTest
by do son · Published September 3, 2017 · Last modified November 4, 2024
Tulpar is a open source web vulnerability scanner for written to make web penetration testing automated. Tulpar has the following features. -Sql Injection (GET Method) -XSS (GET Method) -Crawl -E-mail...
Exploitation / Information Gathering / Network PenTest / Vulnerability Analysis / Web Exploitation / Web Information Gathering / Web Vulnerability Analysis / WebApp PenTest / Wireless
by do son · Published August 30, 2017 · Last modified October 10, 2021
Here is a list of various security tools. Passwords Cain & Abel http://www.oxid.it/cain.html Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published August 27, 2017 · Last modified November 4, 2024
1. A2SV? Auto Scanning to SSL Vulnerability. HeartBleed, CCS Injection, SSLv3 POODLE, FREAK… etc A. Support Vulnerability [CVE-2007-1858] Anonymous Cipher [CVE-2012-4929] CRIME(SDPY) [CVE-2014-0160] CCS Injection [CVE-2014-0224] HeartBleed [CVE-2014-3566] SSLv3 POODLE...
Web Vulnerability Analysis / WebApp PenTest
by do son · Published August 27, 2017 · Last modified November 4, 2024
SQLiv Massive SQL injection vulnerability scanner Features multiple domain scanning with SQL injection dork targetted scanning by providing specific domain (with crawling) reverse domain scanning both SQLi scanning and domain...