Web application fuzzer. Contribute to xmendez/wfuzz development by creating an account on GitHub.
Wfuzz is an outstanding web fuzzer if you don’t have PRO version of Burp.

❣ Chile in a Photography ❣
we're not kids anymore.

Origami Around
NASA

Janaina Medeiros
wallacepolsom

No title available
Keni

★

PR's Tumblrdome
RMH
d e v o n
noise dept.
Lint Roller? I Barely Know Her

titsay

shark vs the universe

pixel skylines
occasionally subtle

ellievsbear

No title available
seen from Türkiye
seen from China
seen from Australia
seen from United Kingdom

seen from United States
seen from United States
seen from United States
seen from United States
seen from United States
seen from United States
seen from United States
seen from United States
seen from United States
seen from United States
seen from United States

seen from South Africa

seen from Norway

seen from United States

seen from Türkiye

seen from India
@websecurityblog
Web application fuzzer. Contribute to xmendez/wfuzz development by creating an account on GitHub.
Wfuzz is an outstanding web fuzzer if you don’t have PRO version of Burp.
The cheat sheet about Java Deserialization vulnerabilities - GrrrDog/Java-Deserialization-Cheat-Sheet
A cheat sheet for pentesters and researchers about deserialization vulnerabilities in various Java (JVM) serialization libraries.
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, ...
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more. The goal is to enable a security tester to pull this repository onto a new testing box and have access to every type of list that may be needed.
Web applications testing guide for penetration testers.
Server-Side Template Injection and Code Injection Detection and Exploitation Tool - epinna/tplmap
Tplmap assists the exploitation of Code Injection and Server-Side Template Injection vulnerabilities with a number of sandbox escape techniques to get access to the underlying operating system. More information about Server-Side Template Injection vulnerability you can find in the Portswigger blog post https://portswigger.net/blog/server-side-template-injection
HTTP parameter discovery suite. Contribute to s0md3v/Arjun development by creating an account on GitHub.
Arjun tool is useful for identifying hidden parameters in WEB applications.
Most advanced XSS scanner. Contribute to s0md3v/XSStrike development by creating an account on GitHub.
XSStrike is a Cross Site Scripting detection suite equipped with four hand written parsers, an intelligent payload generator, a powerful fuzzing engine and an incredibly fast crawler.