webpentest
Here are 35 public repositories matching this topic...
Language:All
Sort:Most stars
All In One Web Recon
- Updated
Apr 30, 2025 - Python
Find S3 AWS/GCP/Azure buckets while surfing. S3DNS acts as DNS server, follows CNAMEs and matches any bucket pattern
- Updated
Sep 10, 2025 - Python
Advanced CORS Header Checker Tool with Vulnerability Detection and Bypass Attempts
- Updated
Jun 6, 2025 - Python
Web Path Finder
- Updated
Nov 22, 2023 - Python
This course uses a deliberately vulnerable banking application to demonstrate common security vulnerabilities, their impact, and how to fix them. The application is built with Flask (backend) and React (frontend).
- Updated
Apr 23, 2025 - JavaScript
Open source self-hosted cyber security learning platform
- Updated
Oct 3, 2022 - TypeScript
CyberSec Resources: FRAMEWORKS & STANDARDS; Pentesting Audits & Hacking; PURPLE TEAMING, AD, API, web, clouds, CTF, OSINT, Pentest tools, Network Security, Privilege escalation, Exploiting, Reversing, Secure Code, Bug Bounty, ...
- Updated
Feb 22, 2023
Whitepass Bypass Whitelist/Ratelimit Implementations in Web Applications/APIs
- Updated
Mar 18, 2021 - Python
Web application pentesting recon
- Updated
Jul 25, 2020 - Shell
The CyberTalents repository is a collection of solutions and write-ups for challenges sourced from the CyberTalents platform. Organized topic, this repository serves as a resource for cybersecurity enthusiasts seeking to enhance their skills and understanding of security concepts.
- Updated
Jun 18, 2025 - Python
Small tool to decode ASP.NET __VIEWSTATE variable when doing webpentests
- Updated
Feb 27, 2021 - Python
This repository discusses the subdomain takeover vulnerability and lists of services which are vulnerable to it. It also provides information, methodology and resources to perform subdomain takeover attacks.
- Updated
Dec 31, 2023 - HTML
A Simple Tool to gather information from any website, domain, sub-domain, DNS, links by enumeration with simple commands.
- Updated
Jun 7, 2024 - Go
Hidden Fuzzer is a URL fuzzing tool designed to uncover hidden paths and resources on web applications. It features multithreading, customizable HTTP headers, and request parameters for optimized performance.
- Updated
Dec 11, 2024 - Go
The simplest way to integrate your subdomain enum outputs with Burp Pro (Fast Crawler)
- Updated
Apr 7, 2022 - Python
This extension allows you to detect implementations of postMessage function, addEventListener("message",function) event handler and onMessage function.
- Updated
Feb 18, 2022 - Python
🎓 Roadmap to conquer PortSwigger Web Security Academy labs — SQLi, XSS, CSRF & more 🛡️🕵️♂️
- Updated
Jun 26, 2025
Erlik 2 - Vulnerable-Flask-App
- Updated
Nov 23, 2023 - Python
a simple vulnerable web applications, gain access then capture the flag.
- Updated
Oct 26, 2021 - PHP
Improve this page
Add a description, image, and links to thewebpentest topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with thewebpentest topic, visit your repo's landing page and select "manage topics."