Mohammad Mukarram's starred repositories

License:Apache-2.0Stargazers:64Issues:0Issues:0

OversecuredVulnerableiOSApp

Oversecured Vulnerable iOS App

Language:SwiftLicense:BSD-2-ClauseStargazers:209Issues:0Issues:0

MXS

A powerful asynchronous XSS scanner supporting up to 1,500 concurrent requests.

Language:PythonStargazers:125Issues:0Issues:0

certainly

Certainly is a offensive security toolkit to capture large amounts of traffic in various network protocols in bitflip and typosquat scenarios.

Language:GoLicense:MITStargazers:101Issues:0Issues:0

weapons4pentester

:hocho: this repo contains required files for web application pentests

Language:ASPStargazers:178Issues:0Issues:0

xss_vibes

A modern tool written in Python that automates your xss findings.

Language:PythonStargazers:348Issues:0Issues:0

BugBountyLearningResources

Bug Bounty Learning Resources i mentioned on My Blog at http://whoami.securitybreached.org/

Stargazers:8Issues:0Issues:0

ParamEnumerator

Hunts for params.

Language:RustStargazers:1Issues:0Issues:0

PizzaHunt

Scans for indications of an XSS, Oracle SQLi and filters out words containing MySQL.

Language:RustLicense:UnlicenseStargazers:28Issues:0Issues:0
Language:ShellStargazers:90Issues:0Issues:0

sqli-dojo-docker

A demo PHP application used to exercise SQL injection techniques in a safe, local Docker environment

Language:PHPLicense:GPL-3.0Stargazers:36Issues:0Issues:0

CRLFsuite

The most powerful CRLF injection (HTTP Response Splitting) scanner.

Language:PythonLicense:MITStargazers:542Issues:0Issues:0

cero

Scrape domain names from SSL certificates of arbitrary hosts

Language:GoLicense:MITStargazers:594Issues:0Issues:0

google-dorks-bug-bounty

A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting

License:MITStargazers:892Issues:0Issues:0

css-scrollbar-attack

PoC for leaking text nodes via CSS injection

Language:JavaScriptStargazers:15Issues:0Issues:0
Language:PythonStargazers:97Issues:0Issues:0

web-check

🕵️‍♂️ All-in-one OSINT tool for analysing any website

Language:TypeScriptLicense:MITStargazers:21734Issues:0Issues:0

apidetector

APIDetector: Efficiently scan for exposed Swagger endpoints across web domains and subdomains. Supports HTTP/HTTPS, multi-threading, and flexible input/output options. Ideal for API security testing.

Language:PythonLicense:MITStargazers:294Issues:0Issues:0

EvenBetter

EvenBetter is a frontend Caido plugin that makes the Caido experience even better 😎

Language:TypeScriptStargazers:122Issues:0Issues:0

Priv8-Nuclei-Templates

My Priv8 Nuclei Templates

Stargazers:278Issues:0Issues:0

awesome-web-hacking

A list of web application security

License:MITStargazers:5717Issues:0Issues:0

bbrf-client

The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices

Language:PythonLicense:MITStargazers:606Issues:0Issues:0

BSQLi

timebased blind sqli with 99% success rate

Language:PythonStargazers:132Issues:0Issues:0

gungnir

CT Log Scanner

Language:GoLicense:MITStargazers:240Issues:0Issues:0

back-me-up

This tool will check for Sensitive Data Leakage with some useful patterns/RegEx. The patterns are mostly targeted on waybackdata and filter everything accordingly.

Language:ShellLicense:MITStargazers:143Issues:0Issues:0

NucleiScanner

NucleiScanner is a Powerful Automation tool for detecting Unknown Vulnerabilities in the Web Applications

Language:ShellLicense:GPL-3.0Stargazers:294Issues:0Issues:0

bbrf-server

The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices

Language:ShellStargazers:286Issues:0Issues:0
Language:PythonLicense:MITStargazers:26Issues:0Issues:0