massito's repositories
formcrawler
This script Crawl the website and find the urls that contains html forms.
shortscan
An IIS short filename enumeration tool
vulnerability-research
This repository contains information on the CVEs I found.
dummy-cloudapp
files for cloudapp.net azure subdomain takeover PoC
scodescanner
SCodeScanner stands for Source Code scanner where the user can scans the source code for finding the Critical Vulnerabilities.
CVE-T4PDF
CVEs and Techniques used PDF as an attack vector.
source-founder
check if the source code compressed and uploaded to the server by mistake
4-ZERO-3
403/401 Bypass Methods + Bash Automation + Your Support ;)
log4j-scan
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
CVE-2021-44228-PoC-log4j-bypass-words
🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - A trick to bypass words blocking patches
webapp-wordlists
This repository contains wordlists for each versions of common web applications and content management systems (CMS). Each version contains a wordlist of all the files directories for this version.
reconftw
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
getJS
A tool to fastly get all javascript sources/files
subjack
Subdomain Takeover tool written in Go
HTTPLeaks
HTTPLeaks - All possible ways, a website can leak HTTP requests
SecretFinder
SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files
WAF-bypass-xss-payloads
XSS payloads for bypassing WAF. This repository is updating continuously.
open-redirector
A small and efficient tool to find open redirect vulnerabilities.
Mind-Maps
Mind-Maps of Several Things
Bug-Bounty-Wordlists
A repository that includes all the important wordlists used while bug hunting.
x8-Burp
Hidden parameters discovery suite
bypass-403
A simple script just made for self use for bypassing 403
client-side-prototype-pollution
Prototype Pollution and useful Script Gadgets
ds_store_exp
A .DS_Store file disclosure exploit. It parses .DS_Store file and downloads files recursively.
sqlscan
A small and an efficient tool to find SQL injection vulnerability in a websites.
bruteforce-lists
Some files for bruteforcing certain things.