GitHub - Ciphey/Ciphey: ⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡ - GitHub - Ciphey/Ciphey: ⚡ Automatically decrypt encryptions without knowing the key or ...
GitHub - projectdiscovery/alterx: Fast and customizable subdomain wordlist generator using DSL
Fast and customizable subdomain wordlist generator using DSL - GitHub - projectdiscovery/alterx: Fast and customizable subdomain wordlist generator using DSL
GitHub - swoops/eval_villain: A Firefox Web Extension to improve the discovery of DOM XSS.
A Firefox Web Extension to improve the discovery of DOM XSS. - GitHub - swoops/eval_villain: A Firefox Web Extension to improve the discovery of DOM XSS.
Захват аккаунта через обход аутентификации SSO с помощью функции входа без пароля
Оригинал статьи на английском тут. Во время поиска багов, я обнаружил функцию входа без пароля. Функция входа без пароля - это функция, которая используется для пользователей учетной записи и позволяет войти в систему без пароля или с помощью OTP (разового пароля), отправленного на привязанный...
Create a Random Text File - Online File Tools
This utility creates text files with random contents. You can customize the file size and adjust what goes in the file. Try it out!
onlinefiletools.com
API Kit is an open source extension, which is a set of tools for detecting, scanning and auditing APIs. It has an active and passive mode.
GitHub - API-Security/APIKit: APIKit:Discovery, Scan and Audit APIs Toolkit All In One.
APIKit:Discovery, Scan and Audit APIs Toolkit All In One. - GitHub - API-Security/APIKit: APIKit:Discovery, Scan and Audit APIs Toolkit All In One.
GitHub - foorilla/allinfosecnews_sources: A list of online news & info sources in the InfoSec/Cybersecurity space
A list of online news & info sources in the InfoSec/Cybersecurity space - GitHub - foorilla/allinfosecnews_sources: A list of online news & info sources in the InfoSec/Cybersecurity space
And IDOR again. Perhaps one of the most insidious vulnerabilities of modern web applications, which, often, can be detected only by manual testing and careful study of the available functionality.
And again Facebook, but now, a vulnerability found when analyzing the basic functionality of the endpoints of a mobile application. A simple step-by-step change of parameters from false to true can lead to unexpected findings.
A tool that allows you to create custom wordlists for a given list of words. It can be useful during directory brutalization.
A selection of repositories on github with useful dorks for Shodan and Censys
good platform for studying common vulnerabilities on the web.