XIƧZDӨƬMY
Open in Telegram
Owner ; @Xisz77DotMy Channel Store ; @cbaiu Feedback ; @feedbackIszKStore @Xisz77DotMy - XIƧZDӨƬMY @XCDotMy - X7DOTMY UPDATE NEWS AND HACKING ACTIVITIES BEFORE BUY PLEASE READ A RULES ALL TRANSFER WITH DIRECT NO REFUNDED IF REFUND MONEY WILL BURN
Show more327
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
327
Nmap waf scanner to check port open and waf active
$nmap -p 80,443 --script=http-waf (url)
Nmap waf fingerprint to check firewall fingerprint
$nmap -p 80,443 --script=waf (url)
327
🛑 Termux Backup commamd
cd $PREFIX/../../;tar -pczvf /sdcard/termux.backup.tar.gz files/;cd;
🛑 Termux Restore command
cd $PREFIX/../../;tar -xzvf /sdcard/termux.backup.tar.gz;cd;
327
Myopecs Pentest tools Apk v1.0 For Android
What is Myopecs Pentest tools APK?
- Collection of tools for penetration testing
Features of Myopecs Pentest tools APK?
- DDoS Attack
- Port Scanner
- DNS Enum
- Directory Buster
- Password Brute-Force
- SMTP Fuzz
Why Do People Like Myopecs Pentest tools APK?
Our tool features an intuitive and user-friendly GUI that simplifies the penetration testing process, making it accessible to both novice and experienced users.
FAQs
Q. Myopecs Pentest tools APK be used on iPhones?
Please note that this application is exclusively designed for Android phones and is not compatible with other operating systems.
Q. IMyopecs Pentest tools APK safe to use?
It was developed by an experienced developer(Mr Hery) and it is safe to use.
Q. Where can i get this apps?
Notes:
The application is still under development. Right now, it can only perform DDoS attacks, but we'll be adding more features in future updates.
327
PenTest Tool App By MyOPECS
Good news for Mobile hackers! We MyOPECS will release an application on Google Playstore & Apple Appstore for PenTest Tool via smartphone!
Here we will update the "development feed" journey for this PenTest Tool.
You can download the latest version of this app through the official topic in the MyOPECS group.
Features:
1. DDoS Toolkit - Done Beta
2. DNS Enum - In progress
3. Port Scanner - In Progress
4. Dir Buster - In Progress
5. Password Attack - In Progress
Meanwhile, the beta-ready function for use is DDoS Toolkit support TCP, UDP and HTTP Flood.
Don't forget to join the MyOPECS Channel here:
https://t.me/MyOPECSPublic
327
(https://github.com/vaib25vicky/awesome-mobile-security) - An effort to build a singleplace for all useful android and iOS security related stuff.awesome-vulnerable-apps (https://github.com/vavkamil/awesome-vulnerable-apps) - Awesome VulnerableApplicationsXFFenum (https://github.com/vavkamil/XFFenum) - X-Forwarded-For [403 forbidden] enumerationhttpx (https://github.com/projectdiscovery/httpx) - httpx is a fast and multi-purpose HTTP toolkit allow to run
327
DNS records.cnames (https://github.com/cybercdh/cnames) - take a list of resolved subdomains and output any correspondingCNAMES en masse.subHijack (https://github.com/vavkamil/old-repos-backup/tree/master/subHijack-master) - Hijacking forgotten &misconfigured subdomainstko-subs (https://github.com/anshumanbh/tko-subs) - A tool that can help detect and takeover subdomains withdead DNS recordsHostileSubBruteforcer (https://github.com/nahamsec/HostileSubBruteforcer) - This app will bruteforce for exisitingsubdomains and provide information if the 3rd party host has been properly setup.second-order (https://github.com/mhmdiaa/second-order) - Second-order subdomain takeover scannertakeover (https://github.com/mzfr/takeover) - A tool for testing subdomain takeover possibilities at a mass scale.dnsReaper (https://github.com/punk-security/dnsReaper) - DNS Reaper is yet another sub-domain takeover tool,but with an emphasis on accuracy, speed and the number of signatures in our arsenal!Vulnerability Scannersnuclei (https://github.com/projectdiscovery/nuclei) - Nuclei is a fast tool for configurable targeted scanning basedon templates offering massive extensibility and ease of use.Sn1per (https://github.com/1N3/Sn1per) - Automated pentest framework for offensive security expertsmetasploit-framework (https://github.com/rapid7/metasploit-framework) - Metasploit Frameworknikto (https://github.com/sullo/nikto) - Nikto web server scannerarachni (https://github.com/Arachni/arachni) - Web Application Security Scanner Frameworkjaeles (https://github.com/jaeles-project/jaeles) - The Swiss Army knife for automated Web Application Testingretire.js (https://github.com/RetireJS/retire.js) - scanner detecting the use of JavaScript libraries with knownvulnerabilitiesOsmedeus (https://github.com/j3ssie/Osmedeus) - Fully automated offensive security framework forreconnaissance and vulnerability scanninggetsploit (https://github.com/vulnersCom/getsploit) - Command line utility for searching and downloading exploitsflan (https://github.com/cloudflare/flan) - A pretty sweet vulnerability scannerFindsploit (https://github.com/1N3/Findsploit) - Find exploits in local and online databases instantlyBlackWidow (https://github.com/1N3/BlackWidow) - A Python based web application scanner to gather OSINTand fuzz for OWASP vulnerabilities on a target website.backslash-powered-scanner (https://github.com/PortSwigger/backslash-powered-scanner) - Finds unknownclasses of injection vulnerabilitiesEagle (https://github.com/BitTheByte/Eagle) - Multithreaded Plugin based vulnerability scanner for mass detectionof web-based applications vulnerabilitiescariddi (https://github.com/edoardottt/cariddi) - Take a list of domains, crawl urls and scan for endpoints, secrets,api keys, file extensions, tokens and more...OWASP ZAP (https://github.com/zaproxy/zaproxy) - World’s most popular free web security tools and is activelymaintained by a dedicated international team of volunteersUncategorizedJSONBee (https://github.com/zigoo0/JSONBee) - A ready to use JSONP endpoints/payloads to help bypasscontent security policy (CSP) of different websites.CyberChef (https://github.com/gchq/CyberChef) - The Cyber Swiss Army Knife - a web app for encryption,encoding, compression and data analysis() -bountyplz (https://github.com/fransr/bountyplz) - Automated security reporting from markdown templates(HackerOne and Bugcrowd are currently the platforms supported)PayloadsAllTheThings (https://github.com/swisskyrepo/PayloadsAllTheThings) - A list of useful payloads andbypass for Web Application Security and Pentest/CTFbounty-targets-data (https://github.com/arkadiyt/bounty-targets-data) - This repo contains hourly-updated datadumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reportsandroid-security-awesome (https://github.com/ashishb/android-security-awesome) - A collection of androidsecurity related resourcesawesome-mobile-security
327
forbugbounty and security testing.mass-s3-bucket-tester (https://github.com/random-robbie/mass-s3-bucket-tester) - This tests a list of s3 bucketsto see if they have dir listings enabled or if they are uploadableS3BucketList (https://github.com/AlecBlance/S3BucketList) - Firefox plugin that lists Amazon S3 Buckets found inrequestsdirlstr (https://github.com/cybercdh/dirlstr) - Finds Directory Listings or open S3 buckets from a list of URLsBurp-AnonymousCloud (https://github.com/codewatchorg/Burp-AnonymousCloud) - Burp extension that performsa passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilitieskicks3 (https://github.com/abuvanth/kicks3) - S3 bucket finder from html,js and bucket misconfiguration testingtool2tearsinabucket (https://github.com/Revenant40/2tearsinabucket) - Enumerate s3 buckets for a specific target.s3_objects_check (https://github.com/nccgroup/s3_objects_check) - Whitebox evaluation of effective S3 objectpermissions, to identify publicly accessible files.s3tk (https://github.com/ankane/s3tk) - A security toolkit for Amazon S3CloudBrute (https://github.com/0xsha/CloudBrute) - Awesome cloud enumerators3cario (https://github.com/0xspade/s3cario) - This tool will get the CNAME first if it's a valid Amazon s3 bucketand if it's not, it will try to check if the domain is a bucket name.S3Cruze (https://github.com/JR0ch17/S3Cruze) - All-in-one AWS S3 bucket tool for pentesters.CMSwpscan (https://github.com/wpscanteam/wpscan) - WPScan is a free, for non-commercial use, black boxWordPress security scannerWPSpider (https://github.com/cyc10n3/WPSpider) - A centralized dashboard for running and schedulingWordPress scans powered by wpscan utility.wprecon (https://github.com/blackcrw/wprecon) - Wordpress ReconCMSmap (https://github.com/Dionach/CMSmap) - CMSmap is a python open source CMS scanner thatautomates the process of detecting security flaws of the most popular CMSs.joomscan (https://github.com/OWASP/joomscan) - OWASP Joomla Vulnerability Scanner Projectpyfiscan (https://github.com/fgeek/pyfiscan) - Free web-application vulnerability and version scannerJSON Web Tokenjwt_tool (https://github.com/ticarpi/jwt_tool) - A toolkit for testing, tweaking and cracking JSON Web Tokensc-jwt-cracker (https://github.com/brendan-rius/c-jwt-cracker) - JWT brute force cracker written in Cjwt-heartbreaker (https://github.com/wallarm/jwt-heartbreaker) - The Burp extension to check JWT (JSON WebTokens) for using keys from known from public sourcesjwtear (https://github.com/KINGSABRI/jwtear) - Modular command-line tool to parse, create and manipulate JWTtokens for hackersjwt-key-id-injector (https://github.com/dariusztytko/jwt-key-id-injector) - Simple python script to check againsthypothetical JWT vulnerability.jwt-hack (https://github.com/hahwul/jwt-hack) - jwt-hack is tool for hacking / security testing to JWT.jwt-cracker (https://github.com/lmammino/jwt-cracker) - Simple HS256 JWT token brute force crackerpostMessagepostMessage-tracker (https://github.com/fransr/postMessage-tracker) - A Chrome Extension to trackpostMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-iconPostMessage_Fuzz_Tool (https://github.com/kiranreddyrebel/PostMessage_Fuzz_Tool) - #BugBounty#BugBounty Tools #WebDeveloper ToolSubdomain Takeoversubjack (https://github.com/haccer/subjack) - Subdomain Takeover tool written in GoSubOver (https://github.com/Ice3man543/SubOver) - A Powerful Subdomain Takeover ToolautoSubTakeover (https://github.com/JordyZomer/autoSubTakeover) - A tool used to check if a CNAME resolvesto the scope address. If the CNAME resolves to a non-scope address it might be worth checking out if subdomaintakeover is possible.NSBrute (https://github.com/shivsahni/NSBrute) - Python utility to takeover domains vulnerable to AWS NSTakeovercan-i-take-over-xyz (https://github.com/EdOverflow/can-i-take-over-xyz) - "Can I take over XYZ?" — a list ofservices and how to claim (sub)domains with dangling
327
Searches through git repositories for high entropy strings andsecrets, digging deep into commit historygitGraber (https://github.com/hisxo/gitGraber) - gitGraber: monitor GitHub to search and find sensitive data in realtime for different online servicestalisman (https://github.com/thoughtworks/talisman) - By hooking into the pre-push hook provided by Git,Talisman validates the outgoing changeset for things that look suspicious - such as authorization tokens andprivate keys.GitGot (https://github.com/BishopFox/GitGot) - Semi-automated, feedback-driven tool to rapidly search throughtroves of public data on GitHub for sensitive secrets.git-all-secrets (https://github.com/anshumanbh/git-all-secrets) - A tool to capture all the git secrets by leveragingmultiple open source git searching toolsgithub-search (https://github.com/gwen001/github-search) - Tools to perform basic search on GitHub.git-vuln-finder (https://github.com/cve-search/git-vuln-finder) - Finding potential software vulnerabilities from gitcommit messagescommit-stream (https://github.com/x1sec/commit-stream) - #OSINT tool for finding Github repositories byextracting commit logs in real time from the Github event APIgitrob (https://github.com/michenriksen/gitrob) - Reconnaissance tool for GitHub organizationsrepo-supervisor (https://github.com/auth0/repo-supervisor) - Scan your code for security misconfiguration, searchfor passwords and secrets.GitMiner (https://github.com/UnkL4b/GitMiner) - Tool for advanced mining for content on Githubshhgit (https://github.com/eth0izzle/shhgit) - Ah shhgit! Find GitHub secrets in real timedetect-secrets (https://github.com/Yelp/detect-secrets) - An enterprise friendly way of detecting and preventingsecrets in code.rusty-hog (https://github.com/newrelic/rusty-hog) - A suite of secret scanners built in Rust for performance. Basedon TruffleHogwhispers (https://github.com/Skyscanner/whispers) - Identify hardcoded secrets and dangerous behavioursyar (https://github.com/nielsing/yar) - Yar is a tool for plunderin' organizations, users and/or repositories.dufflebag (https://github.com/BishopFox/dufflebag) - Search exposed EBS volumes for secretssecret-bridge (https://github.com/duo-labs/secret-bridge) - Monitors Github for leaked secretsearlybird (https://github.com/americanexpress/earlybird) - EarlyBird is a sensitive data detection tool capable ofscanning source code repositories for clear text password violations, PII, outdated cryptography methods, keyfiles and more.Trufflehog-Chrome-Extension (https://github.com/trufflesecurity/Trufflehog-Chrome-Extension) - Trufflehog Chrome-ExtensionGitGitTools (https://github.com/internetwache/GitTools) - A repository with 3 tools for pwn'ing websites with .gitrepositories availablegitjacker (https://github.com/liamg/gitjacker) - Leak git repositories from misconfigured websitesgit-dumper (https://github.com/arthaud/git-dumper) - A tool to dump a git repository from a websiteGitHunter (https://github.com/digininja/GitHunter) - A tool for searching a Git repository for interesting contentdvcs-ripper (https://github.com/kost/dvcs-ripper) - Rip web accessible (distributed) version control systems:SVN/GIT/HG...BucketsS3Scanner (https://github.com/sa7mon/S3Scanner) - Scan for open AWS S3 buckets and dump the contentsAWSBucketDump (https://github.com/jordanpotti/AWSBucketDump) - Security Tool to Look For Interesting Filesin S3 BucketsCloudScraper (https://github.com/jordanpotti/CloudScraper) - CloudScraper: Tool to enumerate targets in searchof cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.s3viewer (https://github.com/SharonBrizinov/s3viewer) - Publicly Open Amazon AWS S3 Bucket Viewerfestin (https://github.com/cr0hn/festin) - FestIn - S3 Bucket Weakness Discoverys3reverse (https://github.com/hahwul/s3reverse) - The format of various s3 buckets is convert in one format.
327
Correlated injection proxy tool forXSS Hunterextended-xss-search (https://github.com/Damian89/extended-xss-search) - A better version of my xssfinder tool -scans for different types of xss on a list of urls.xssmap (https://github.com/Jewel591/xssmap) - XSSMap 是一款基于 Python3 开发用于检测 XSS 漏洞的工具XSSCon (https://github.com/menkrep1337/XSSCon) - XSSCon: Simple XSS Scanner toolBitBlinder (https://github.com/BitTheByte/BitBlinder) - BurpSuite extension to inject custom cross-site scriptingpayloads on every form/request submitted to detect blind XSS vulnerabilitiesXSSOauthPersistence (https://github.com/dxa4481/XSSOauthPersistence) - Maintaining account persistence viaXSS and Oauthshadow-workers (https://github.com/shadow-workers/shadow-workers) - Shadow Workers is a free and opensource C2 and proxy designed for penetration testers to help in the exploitation of XSS and malicious ServiceWorkers (SW)rexsser (https://github.com/profmoriarity/rexsser) - This is a burp plugin that extracts keywords from responseusing regexes and test for reflected XSS on the target scope.xss-flare (https://github.com/EgeBalci/xss-flare) - XSS hunter on cloudflare serverless workers.Xss-Sql-Fuzz (https://github.com/jiangsir404/Xss-Sql-Fuzz) - burpsuite 插件对GP所有参数(过滤特殊参数)一键自动添加xss sql payload 进行fuzzvaya-ciego-nen (https://github.com/hipotermia/vaya-ciego-nen) - Detect, manage and exploit Blind Cross-sitescripting (XSS) vulnerabilities.dom-based-xss-finder (https://github.com/AsaiKen/dom-based-xss-finder) - Chrome extension that finds DOMbased XSS vulnerabilitiesXSSTerminal (https://github.com/machinexa2/XSSTerminal) - Develop your own XSS Payload using interactivetypingxss2png (https://github.com/vavkamil/xss2png) - PNG IDAT chunks XSS payload generatorXSSwagger (https://github.com/vavkamil/XSSwagger) - A simple Swagger-ui scanner that can detect old versionsvulnerable to various XSS attacksXXE Injectionground-control (https://github.com/jobertabma/ground-control) - A collection of scripts that run on my web server.Mainly for debugging SSRF, blind XSS, and XXE vulnerabilities.dtd-finder (https://github.com/GoSecure/dtd-finder) - List DTDs and generate XXE payloads using those localDTDs.docem (https://github.com/whitel1st/docem) - Uility to embed XXE and XSS payloads in docx,odt,pptx,etc(OXML_XEE on steroids)xxeserv (https://github.com/staaldraad/xxeserv) - A mini webserver with FTP support for XXE payloadsxxexploiter (https://github.com/luisfontes19/xxexploiter) - Tool to help exploit XXE vulnerabilitiesB-XSSRF (https://github.com/SpiderMate/B-XSSRF) - Toolkit to detect and keep track on Blind XSS, XXE &SSRFXXEinjector (https://github.com/enjoiz/XXEinjector) - Tool for automatic exploitation of XXE vulnerability usingdirect and different out of band methods.oxml_xxe (https://github.com/BuffaloWill/oxml_xxe) - A tool for embedding XXE/XML exploits into differentfiletypesmetahttp (https://github.com/vp777/metahttp) - A bash script that automates the scanning of a target network forHTTP resources through XXEMiscellaneousLorem ipsum dolor sit ametPasswordsthc-hydra (https://github.com/vanhauser-thc/thc-hydra) - Hydra is a parallelized login cracker which supportsnumerous protocols to attack.DefaultCreds-cheat-sheet (https://github.com/ihebski/DefaultCreds-cheat-sheet) - One place for all the defaultcredentials to assist the Blue/Red teamers activities on finding devices with default passwordchangeme (https://github.com/ztgrace/changeme) - A default credential scanner.BruteX (https://github.com/1N3/BruteX) - Automatically brute force all services running on a target.patator (https://github.com/lanjelot/patator) - Patator is a multi-purpose brute-forcer, with a modular design and aflexible usage.Secretsgit-secrets (https://github.com/awslabs/git-secrets) - Prevents you from committing secrets and credentials into gitrepositoriesgitleaks (https://github.com/zricethezav/gitleaks) - Scan git repos (or files) for secrets using regex and entropytruffleHog (https://github.com/dxa4481/truffleHog) -
327
from waybackmachine then test each GET parameter for sql injection.ESC (https://github.com/NetSPI/ESC) - Evil SQL Client (ESC) is an interactive .NET SQL console client withenhanced SQL Server discovery, access, and data exfiltration features.mssqli-duet (https://github.com/Keramas/mssqli-duet) - SQL injection script for MSSQL that extracts domainusers from an Active Directory environment based on RID bruteforcingburp-to-sqlmap (https://github.com/Miladkhoshdel/burp-to-sqlmap) - Performing SQLInjection test on Burp SuiteBulk Requests using SQLMapBurpSQLTruncSanner (https://github.com/InitRoot/BurpSQLTruncSanner) - Messy BurpSuite plugin for SQLTruncation vulnerabilities.andor (https://github.com/sadicann/andor) - Blind SQL Injection Tool with GolangBlinder (https://github.com/mhaskar/Blinder) - A python library to automate time-based blind SQL injectionsqliv (https://github.com/the-robot/sqliv) - massive SQL injection vulnerability scannernosqli (https://github.com/Charlie-belmer/nosqli) - NoSql Injection CLI tool, for finding vulnerable websites usingMongoDB.XSS InjectionXSStrike (https://github.com/s0md3v/XSStrike) - Most advanced XSS scanner.xssor2 (https://github.com/evilcos/xssor2) - XSS'OR - Hack with JavaScript.xsscrapy (https://github.com/DanMcInerney/xsscrapy) - XSS spider - 66/66 wavsep XSS detectedsleepy-puppy (https://github.com/Netflix-Skunkworks/sleepy-puppy) - Sleepy Puppy XSS Payload ManagementFrameworkezXSS (https://github.com/ssl/ezXSS) - ezXSS is an easy way for penetration testers and bug bounty hunters totest (blind) Cross Site Scripting.xsshunter (https://github.com/mandatoryprogrammer/xsshunter) - The XSS Hunter service - a portable version ofXSSHunter.comdalfox (https://github.com/hahwul/dalfox) - DalFox(Finder Of XSS) / Parameter Analysis and XSS Scanning toolbased on golangxsser (https://github.com/epsylon/xsser) - Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect,exploit and report XSS vulnerabilities in web-based applications.XSpear (https://github.com/hahwul/XSpear) - Powerfull XSS Scanning and Parameter analysis tool&gemweaponised-XSS-payloads (https://github.com/hakluke/weaponised-XSS-payloads) - XSS payloads designed toturn alert(1) into P1tracy (https://github.com/nccgroup/tracy) - A tool designed to assist with finding all sinks and sources of a webapplication and display these results in a digestible manner.ground-control (https://github.com/jobertabma/ground-control) - A collection of scripts that run on my web server.Mainly for debugging SSRF, blind XSS, and XXE vulnerabilities.xssValidator (https://github.com/nVisium/xssValidator) - This is a burp intruder extender that is designed forautomation and validation of XSS vulnerabilities.JSShell (https://github.com/Den1al/JSShell) - An interactive multi-user web JS shellbXSS (https://github.com/LewisArdern/bXSS) - bXSS is a utility which can be used by bug hunters andorganizations to identify Blind Cross-Site Scripting.docem (https://github.com/whitel1st/docem) - Uility to embed XXE and XSS payloads in docx,odt,pptx,etc(OXML_XEE on steroids)XSS-Radar (https://github.com/bugbountyforum/XSS-Radar) - XSS Radar is a tool that detects parameters andfuzzes them for cross-site scripting vulnerabilities.BruteXSS (https://github.com/rajeshmajumdar/BruteXSS) - BruteXSS is a tool written in python simply to find XSSvulnerabilities in web application.findom-xss (https://github.com/dwisiswant0/findom-xss) - A fast DOM based XSS vulnerability scanner withsimplicity.domdig (https://github.com/fcavallarin/domdig) - DOM XSS scanner for Single Page Applicationsfemida (https://github.com/wish-i-was/femida) - Automated blind-xss search for Burp SuiteB-XSSRF (https://github.com/SpiderMate/B-XSSRF) - Toolkit to detect and keep track on Blind XSS, XXE &SSRFdomxssscanner (https://github.com/yaph/domxssscanner) - DOMXSS Scanner is an online tool to scan sourcecode for DOM based XSS vulnerabilitiesxsshunter_client (https://github.com/mandatoryprogrammer/xsshunter_client) -
327
applications.Includes a RESTful API to integrate into a continuous integration pipeline.Request Smugglinghttp-request-smuggling (https://github.com/anshumanpattnaik/http-request-smuggling) - HTTP RequestSmuggling Detection Toolsmuggler (https://github.com/defparam/smuggler) - Smuggler - An HTTP Request Smuggling / Desync testing toolwritten in Python 3h2csmuggler (https://github.com/BishopFox/h2csmuggler) - HTTP Request Smuggling over HTTP/2 Cleartext(h2c)tiscripts (https://github.com/defparam/tiscripts) - These scripts I use to create Request Smuggling Desyncpayloads for CLTE and TECL style attacks.Server Side Request ForgerySSRFmap (https://github.com/swisskyrepo/SSRFmap) - Automatic SSRF fuzzer and exploitation toolGopherus (https://github.com/tarunkant/Gopherus) - This tool generates gopher link for exploiting SSRF andgaining RCE in various serversground-control (https://github.com/jobertabma/ground-control) - A collection of scripts that run on my web server.Mainly for debugging SSRF, blind XSS, and XXE vulnerabilities.SSRFire (https://github.com/micha3lb3n/SSRFire) - An automated SSRF finder. Just give the domain name andyour server and chill! ;) Also has options to find XSS and open redirectshttprebind (https://github.com/daeken/httprebind) - Automatic tool for DNS rebinding-based SSRF attacksssrf-sheriff (https://github.com/teknogeek/ssrf-sheriff) - A simple SSRF-testing sheriff written in GoB-XSSRF (https://github.com/SpiderMate/B-XSSRF) - Toolkit to detect and keep track on Blind XSS, XXE &SSRFextended-ssrf-search (https://github.com/Damian89/extended-ssrf-search) - Smart ssrf scanner using differentmethods like parameter brute forcing in post and get...gaussrf (https://github.com/KathanP19/gaussrf) - Fetch known URLs from AlienVault's Open Threat Exchange,the Wayback Machine, and Common Crawl and Filter Urls With OpenRedirection or SSRF Parameters.ssrfDetector (https://github.com/JacobReynolds/ssrfDetector) - Server-side request forgery detectorgrafana-ssrf (https://github.com/RandomRobbieBF/grafana-ssrf) - Authenticated SSRF in GrafanasentrySSRF (https://github.com/xawdxawdx/sentrySSRF) - Tool to searching sentry config on page or injavascript files and check blind SSRFlorsrf (https://github.com/knassar702/lorsrf) - Bruteforcing on Hidden parameters to find SSRF vulnerability usingGET and POST Methodssingularity (https://github.com/nccgroup/singularity) - A DNS rebinding attack framework.whonow (https://github.com/brannondorsey/whonow) - A "malicious" DNS server for executing DNS Rebindingattacks on the fly (public instance running on rebind.network:53)dns-rebind-toolkit (https://github.com/brannondorsey/dns-rebind-toolkit) - A front-end JavaScript toolkit forcreating DNS rebinding attacks.dref (https://github.com/FSecureLABS/dref) - DNS Rebinding Exploitation Frameworkrbndr (https://github.com/taviso/rbndr) - Simple DNS Rebinding Servicehttprebind (https://github.com/daeken/httprebind) - Automatic tool for DNS rebinding-based SSRF attacksdnsFookup (https://github.com/makuga01/dnsFookup) - DNS rebinding toolkitSQL Injectionsqlmap (https://github.com/sqlmapproject/sqlmap) - Automatic SQL injection and database takeover toolNoSQLMap (https://github.com/codingo/NoSQLMap) - Automated NoSQL database enumeration and webapplication exploitation tool.SQLiScanner (https://github.com/0xbug/SQLiScanner) - Automatic SQL injection with Charles and sqlmap apiSleuthQL (https://github.com/RhinoSecurityLabs/SleuthQL) - Python3 Burp History parsing tool to discoverpotential SQL injection points. To be used in tandem with SQLmap.mssqlproxy (https://github.com/blackarrowsec/mssqlproxy) - mssqlproxy is a toolkit aimed to perform lateralmovement in restricted environments through a compromised Microsoft SQL Server via socket reusesqli-hunter (https://github.com/zt2/sqli-hunter) - SQLi-Hunter is a simple HTTP / HTTPS proxy server and aSQLMAP API wrapper that makes digging SQLi easy.waybackSqliScanner (https://github.com/ghostlulzhacks/waybackSqliScanner) - Gather urls
327
(https://github.com/dwisiswant0/crlfuzz) - A fast tool to scan CRLF vulnerability written in GoCRLF-Injection-Scanner (https://github.com/MichaelStott/CRLF-Injection-Scanner) - Command line tool for testingCRLF injection on a list of domains.Injectus (https://github.com/BountyStrike/Injectus) - CRLF and open redirect fuzzerCSRF InjectionXSRFProbe (https://github.com/0xInfection/XSRFProbe) -The Prime Cross Site Request Forgery (CSRF) Auditand Exploitation Toolkit.Directory Traversaldotdotpwn (https://github.com/wireghoul/dotdotpwn) - DotDotPwn - The Directory Traversal FuzzerFDsploit (https://github.com/chrispetrou/FDsploit) - File Inclusion & Directory Traversal fuzzing, enumeration &exploitation tool.off-by-slash (https://github.com/bayotop/off-by-slash) - Burp extension to detect alias traversal via NGINXmisconfiguration at scale.liffier (https://github.com/momenbasel/liffier) - tired of manually add dot-dot-slash to your possible path traversal?this short snippet will increment ../ on the URL.File Inclusionliffy (https://github.com/mzfr/liffy) - Local file inclusion exploitation toolBurp-LFI-tests (https://github.com/Team-Firebugs/Burp-LFI-tests) - Fuzzing for LFI using BurpsuiteLFI-Enum (https://github.com/mthbernardes/LFI-Enum) - Scripts to execute enumeration via LFILFISuite (https://github.com/D35m0nd142/LFISuite) - Totally Automatic LFI Exploiter (+ Reverse Shell) andScannerLFI-files (https://github.com/hussein98d/LFI-files) - Wordlist to bruteforce for LFIGraphQL Injectioninql (https://github.com/doyensec/inql) - InQL - A Burp Extension for GraphQL Security TestingGraphQLmap (https://github.com/swisskyrepo/GraphQLmap) - GraphQLmap is a scripting engine to interact witha graphql endpoint for pentesting purposes.shapeshifter (https://github.com/szski/shapeshifter) - GraphQL security testing toolgraphql_beautifier (https://github.com/zidekmat/graphql_beautifier) - Burp Suite extension to help make Graphqlrequest more readableclairvoyance (https://github.com/nikitastupin/clairvoyance) - Obtain GraphQL API schema despite disabledintrospection!Header Injectionheadi (https://github.com/mlcsec/headi) - Customisable and automated HTTP header injection.Insecure Deserializationysoserial (https://github.com/frohoff/ysoserial) - A proof-of-concept tool for generating payloads that exploit unsafeJava object deserialization.GadgetProbe (https://github.com/BishopFox/GadgetProbe) - Probe endpoints consuming Java serialized objectsto identify classes, libraries, and library versions on remote Java classpaths.ysoserial.net (https://github.com/pwntester/ysoserial.net) - Deserialization payload generator for a variety of .NETformattersphpggc (https://github.com/ambionics/phpggc) - PHPGGC is a library of PHP unserialize() payloads along with atool to generate them, from command line or programmatically.Insecure Direct Object ReferencesAutorize (https://github.com/Quitten/Autorize) - Automatic authorization enforcement detection extension for burpsuite written in Jython developed by Barak TawilyOpen RedirectOralyzer (https://github.com/r0075h3ll/Oralyzer) - Open Redirection AnalyzerInjectus (https://github.com/BountyStrike/Injectus) - CRLF and open redirect fuzzerdom-red (https://github.com/Naategh/dom-red) - Small script to check a list of domains against open redirectvulnerabilityOpenRedireX (https://github.com/devanshbatham/OpenRedireX) - A Fuzzer for OpenRedirect issuesRace Conditionrazzer (https://github.com/compsec-snu/razzer) - A Kernel fuzzer focusing on race bugsracepwn (https://github.com/racepwn/racepwn) - Race Condition frameworkrequests-racer (https://github.com/nccgroup/requests-racer) - Small Python library that makes it easy to exploitrace conditions in web apps with Requests.turbo-intruder (https://github.com/PortSwigger/turbo-intruder) - Turbo Intruder is a Burp Suite extension forsending large numbers of HTTP requests and analyzing the results.race-the-web (https://github.com/TheHackerDev/race-the-web) - Tests for race conditions in web
327
dirbuster-ng is C CLI implementation of the Javadirbuster toolgospider (https://github.com/jaeles-project/gospider) - Gospider - Fast web spider written in Gohakrawler (https://github.com/hakluke/hakrawler) - Simple, fast web crawler designed for easy, quick discovery ofendpoints and assets within a web applicationcrawley (https://github.com/s0rg/crawley) - fast, feature-rich unix-way web scraper/crawler written in Golang.LinksLinkFinder (https://github.com/GerbenJavado/LinkFinder) - A python script that finds endpoints in JavaScript filesJS-Scan (https://github.com/zseano/JS-Scan) - a .js scanner, built in php. designed to scrape urls and other infoLinksDumper (https://github.com/arbazkiraak/LinksDumper) - Extract (links/possible endpoints) from responses &filter them via decoding/sortingGoLinkFinder (https://github.com/0xsha/GoLinkFinder) - A fast and minimal JS endpoint extractorBurpJSLinkFinder (https://github.com/InitRoot/BurpJSLinkFinder) - Burp Extension for a passive scanning JS filesfor endpoint links.urlgrab (https://github.com/IAmStoxe/urlgrab) - A golang utility to spider through a website searching for additionallinks.waybackurls (https://github.com/tomnomnom/waybackurls) - Fetch all the URLs that the Wayback Machine knowsabout for a domaingau (https://github.com/lc/gau) - Fetch known URLs from AlienVault's Open Threat Exchange, the WaybackMachine, and Common Crawl.getJS (https://github.com/003random/getJS) - A tool to fastly get all javascript sources/fileslinx (https://github.com/riza/linx) - Reveals invisible links within JavaScript filesParametersparameth (https://github.com/maK-/parameth) - This tool can be used to brute discover GET and POSTparametersparam-miner (https://github.com/PortSwigger/param-miner) - This extension identifies hidden, unlinkedparameters. It's particularly useful for finding web cache poisoning vulnerabilities.ParamPamPam (https://github.com/Bo0oM/ParamPamPam) - This tool for brute discover GET and POSTparameters.Arjun (https://github.com/s0md3v/Arjun) - HTTP parameter discovery suite.ParamSpider (https://github.com/devanshbatham/ParamSpider) - Mining parameters from dark corners of WebArchives.x8 (https://github.com/Sh1Yo/x8) - Hidden parameters discovery suite written in Rust.Fuzzingwfuzz (https://github.com/xmendez/wfuzz) - Web application fuzzerffuf (https://github.com/ffuf/ffuf) - Fast web fuzzer written in Gofuzzdb (https://github.com/fuzzdb-project/fuzzdb) - Dictionary of attack patterns and primitives for black-boxapplication fault injection and resource discovery.IntruderPayloads (https://github.com/1N3/IntruderPayloads) - A collection of Burpsuite Intruder payloads,BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.fuzz.txt (https://github.com/Bo0oM/fuzz.txt) - Potentially dangerous filesfuzzilli (https://github.com/googleprojectzero/fuzzilli) - A JavaScript Engine Fuzzerfuzzapi (https://github.com/Fuzzapi/fuzzapi) - Fuzzapi is a tool used for REST API pentesting and usesAPI_Fuzzer gemqsfuzz (https://github.com/ameenmaali/qsfuzz) - qsfuzz (Query String Fuzz) allows you to build your own rules tofuzz query strings and easily identify vulnerabilities.vaf (https://github.com/d4rckh/vaf) - very advanced (web) fuzzer written in Nim.ExploitationLorem ipsum dolor sit ametCommand Injectioncommix (https://github.com/commixproject/commix) - Automated All-in-One OS command injection andexploitation tool.CORS MisconfigurationCorsy (https://github.com/s0md3v/Corsy) - CORS Misconfiguration ScannerCORStest (https://github.com/RUB-NDS/CORStest) - A simple CORS misconfiguration scannercors-scanner (https://github.com/laconicwolf/cors-scanner) - A multi-threaded scanner that helps identify CORSflaws/misconfigurationsCorsMe (https://github.com/Shivangx01b/CorsMe) - Cross Origin Resource Sharing MisConfiguration ScannerCRLF InjectionCRLFsuite (https://github.com/Nefcore/CRLFsuite) - A fast tool specially designed to scan CRLF injectioncrlfuzz
327
(https://github.com/3nock/sub3suite) - A research-grade suite of tools for subdomain enumeration,intelligence gathering and attack surface mapping.Port Scanningmasscan (https://github.com/robertdavidgraham/masscan) - TCP port scanner, spews SYN packetsasynchronously, scanning entire Internet in under 5 minutes.RustScan (https://github.com/RustScan/RustScan) - The Modern Port Scannernaabu (https://github.com/projectdiscovery/naabu) - A fast port scanner written in go with focus on reliability andsimplicity.nmap (https://github.com/nmap/nmap) - Nmap - the Network Mapper. Github mirror of official SVN repository.sandmap (https://github.com/trimstray/sandmap) - Nmap on steroids. Simple CLI with the ability to run pure Nmapengine, 31 modules with 459 scan profiles.ScanCannon (https://github.com/johnnyxmas/ScanCannon) - Combines the speed of masscan with the reliabilityand detailed enumeration of nmapScreenshotsEyeWitness (https://github.com/FortyNorthSecurity/EyeWitness) - EyeWitness is designed to take screenshots ofwebsites, provide some server header info, and identify default credentials if possible.aquatone (https://github.com/michenriksen/aquatone) - Aquatone is a tool for visual inspection of websites acrossa large amount of hosts and is convenient for quickly gaining an overview of HTTP-based attack surface.screenshoteer (https://github.com/vladocar/screenshoteer) - Make website screenshots and mobile emulationsfrom the command line.gowitness (https://github.com/sensepost/gowitness) - gowitness - a golang, web screenshot utility using ChromeHeadlessWitnessMe (https://github.com/byt3bl33d3r/WitnessMe) - Web Inventory tool, takes screenshots of webpagesusing Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.eyeballer (https://github.com/BishopFox/eyeballer) - Convolutional neural network for analyzing pentestscreenshotsscrying (https://github.com/nccgroup/scrying) - A tool for collecting RDP, web and VNC screenshots all in oneplaceDepix (https://github.com/beurtschipper/Depix) - Recovers passwords from pixelized screenshotshttpscreenshot (https://github.com/breenmachine/httpscreenshot/) - HTTPScreenshot is a tool for grabbingscreenshots and HTML of large numbers of websites.Technologieswappalyzer (https://github.com/AliasIO/wappalyzer) - Identify technology on websites.webanalyze (https://github.com/rverton/webanalyze) - Port of Wappalyzer (uncovers technologies used onwebsites) to automate mass scanning.python-builtwith (https://github.com/claymation/python-builtwith) - BuiltWith API clientwhatweb (https://github.com/urbanadventurer/whatweb) - Next generation web scannerretire.js (https://github.com/RetireJS/retire.js) - scanner detecting the use of JavaScript libraries with knownvulnerabilitieshttpx (https://github.com/projectdiscovery/httpx) - httpx is a fast and multi-purpose HTTP toolkit allows to runmultiple probers using retryablehttp library, it is designed to maintain the result reliability with increased threads.fingerprintx (https://github.com/praetorian-inc/fingerprintx) - fingerprintx is a standalone utility for service discoveryon open ports that works well with other popular bug bounty command line tools.Content Discoverygobuster (https://github.com/OJ/gobuster) - Directory/File, DNS and VHost busting tool written in Gorecursebuster (https://github.com/C-Sto/recursebuster) - rapid content discovery tool for recursively queryingwebservers, handy in pentesting and web application assessmentsferoxbuster (https://github.com/epi052/feroxbuster) - A fast, simple, recursive content discovery tool written inRust.dirsearch (https://github.com/maurosoria/dirsearch) - Web path scannerdirsearch (https://github.com/evilsocket/dirsearch) - A Go implementation of dirsearch.filebuster (https://github.com/henshin/filebuster) - An extremely fast and flexible web fuzzerdirstalk (https://github.com/stefanoj3/dirstalk) - Modern alternative to dirbuster/dirbdirbuster-ng (https://github.com/digination/dirbuster-ng) -
327
ReconLorem ipsum dolor sit ametSubdomain EnumerationSublist3r (https://github.com/aboul3la/Sublist3r) - Fast subdomains enumeration tool for penetration testersAmass (https://github.com/OWASP/Amass) - In-depth Attack Surface Mapping and Asset Discoverymassdns (https://github.com/blechschmidt/massdns) - A high-performance DNS stub resolver for bulk lookupsand reconnaissance (subdomain enumeration)Findomain (https://github.com/Findomain/Findomain) - The fastest and cross-platform subdomain enumerator, donot waste your time.Sudomy (https://github.com/Screetsec/Sudomy) - Sudomy is a subdomain enumeration tool to collectsubdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentestingchaos-client (https://github.com/projectdiscovery/chaos-client) - Go client to communicate with Chaos DNS API.domained (https://github.com/TypeError/domained) - Multi Tool Subdomain Enumerationbugcrowd-levelup-subdomain-enumeration (https://github.com/appsecco/bugcrowd-levelup-subdomain enumeration) - This repository contains all the material from the talk "Esoteric sub-domain enumerationtechniques" given at Bugcrowd LevelUp 2017 virtual conferenceshuffledns (https://github.com/projectdiscovery/shuffledns) - shuffleDNS is a wrapper around massdns written ingo that allows you to enumerate valid subdomains using active bruteforce as well as resolve subdomains withwildcard handling and easy input-output…censys-subdomain-finder (https://github.com/christophetd/censys-subdomain-finder) - Perform subdomainenumeration using the certificate transparency logs from Censys.Turbolist3r (https://github.com/fleetcaptain/Turbolist3r) - Subdomain enumeration tool with analysis features fordiscovered domainscensys-enumeration (https://github.com/0xbharath/censys-enumeration) - A script to extract subdomains/emailsfor a given domain using SSL/TLS certificate dataset on Censystugarecon (https://github.com/LordNeoStark/tugarecon) - Fast subdomains enumeration tool for penetrationtesters.as3nt (https://github.com/cinerieus/as3nt) - Another Subdomain ENumeration ToolSubra (https://github.com/si9int/Subra) - A Web-UI for subdomain enumeration (subfinder)Substr3am (https://github.com/nexxai/Substr3am) - Passive reconnaissance/enumeration of interesting targets bywatching for SSL certificates being issueddomain (https://github.com/jhaddix/domain/) - enumall.py Setup script for Regon-ngaltdns (https://github.com/infosec-au/altdns) - Generates permutations, alterations and mutations of subdomainsand then resolves thembrutesubs (https://github.com/anshumanbh/brutesubs) - An automation framework for running multiple opensourced subdomain bruteforcing tools (in parallel) using your own wordlists via Docker Composedns-parallel-prober (https://github.com/lorenzog/dns-parallel-prober) - his is a parallelised domain name prober tofind as many subdomains of a given domain as fast as possible.dnscan (https://github.com/rbsec/dnscan) - dnscan is a python wordlist-based DNS subdomain scanner.knock (https://github.com/guelfoweb/knock) - Knockpy is a python tool designed to enumerate subdomains on atarget domain through a wordlist.hakrevdns (https://github.com/hakluke/hakrevdns) - Small, fast tool for performing reverse DNS lookups enmasse.dnsx (https://github.com/projectdiscovery/dnsx) - Dnsx is a fast and multi-purpose DNS toolkit allow to runmultiple DNS queries of your choice with a list of user-supplied resolvers.subfinder (https://github.com/projectdiscovery/subfinder) - Subfinder is a subdomain discovery tool that discoversvalid subdomains for websites.assetfinder (https://github.com/tomnomnom/assetfinder) - Find domains and subdomains related to a givendomaincrtndstry (https://github.com/nahamsec/crtndstry) - Yet another subdomain finderVHostScan (https://github.com/codingo/VHostScan) - A virtual host scanner that performs reverse lookupsscilla (https://github.com/edoardottt/scilla) - Information Gathering tool - DNS / Subdomains / Ports / Directoriesenumerationsub3suite
327
Kita guna #Israelcuak pula kali ini.
Ayuh naikkan gelombang ini supaya semua orang tahu apa yang berlaku di Palestin kali ini.
Ikuti juga tanda pagar berikut untuk memastikan anda tidak ketinggalan dengan berita berkaitan.
Ayuuuhhhhh!
#israelkoyak
#taufanalaqsa
