amass
Cppcheck
Our great sponsors
amass | Cppcheck | |
---|---|---|
19 | 11 | |
11,069 | 5,389 | |
3.0% | - | |
7.5 | 9.9 | |
25 days ago | 4 days ago | |
Go | C++ | |
GNU General Public License v3.0 or later | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
amass
-
amass VS dmut - a user suggested alternative
2 projects | 29 Nov 2023
-
findomain VS amass - a user suggested alternative
2 projects | 24 Nov 2023
-
Looking for Recommendations for New Vulnerability & PHI/PII Scanner
OWASP Zap, OWASP Amass, OpenVAS Scanner
-
Can authenticated internet-facing web app be discovered if not indexed by search engines?
My main source is Certificate Transparency, which is kind of a database of TLS certs created so far. But use external tools like Subfinder or Amass.
-
Millions of .git folders exposed publicly by mistake
Scan our domains and infrastructure to reveal if we have exposed.git repositories and other critical infrastructure. You can scan your domains and subdomains with many tools such as Amass or dirsearch to name a couple.
-
Tools for subdomain brute forcing
Amass = https://github.com/OWASP/Amass
-
A new free, open source, cross platform OSINT Tool
Mostly by researching the OSINT sources that other open source project pulls data from e.g amass, spiderfoot, the Harvetser etc
-
Awesome Penetration Testing
OWASP Amass - Subdomain enumeration via scraping, web archives, brute forcing, permutations, reverse DNS sweeping, TLS certificates, passive DNS data sources, etc.
- Laramies / TheHarvester Emails, Subdomains and Names Harvester – Osint
-
Clarification on Black Box Pentesting
On the subdomain part you may want to use amass https://github.com/OWASP/Amass
Cppcheck
-
Configuring Cppcheck, Cpplint, and JSON Lint
I dedicated Sunday morning to going over the documentation of the linters we use in the project. The goal was to understand all options and use them in the best way for our project. Seeing their manuals side by side was nice because even very similar things are solved differently. Cppcheck is the most configurable and best documented; JSON Lint lies at the other end.
-
Enforcing Memory Safety?
Using infer, someone else exploited null-dereference checks to introduce simple affine types in C++. Cppcheck also checks for null-dereferences. Unfortunately, that approach means that borrow-counting references have a larger sizeof than non-borrow counting references, so optimizing the count away potentially changes the semantics of a program which introduces a whole new way of writing subtly wrong code.
-
Check out my tasks.json for C++ of VScode
Also check out (cppcheck)[https://github.com/danmar/cppcheck] if you want more static analysis
-
What are the must-have tools for any C++ developer?
My browser refuses to open that link. This is better: https://github.com/danmar/cppcheck
-
Awesome Penetration Testing
cppcheck - Extensible C/C++ static analyzer focused on finding bugs.
-
C/C++ pre-commit hooks for static analyzers and linters
and five C/C++ static code analyzers: * clang-tidy * oclint * cppcheck * cpplint (recently added!) * include-what-you-use (recently added!)
-
C Deep
Cppcheck - Static analysis tool. Despite the name, works well with C. GPL-3.0-or-later
What are some alternatives?
subfinder - Fast passive subdomain enumeration tool.
cpplint - Static code checker for C++
assetfinder - Find domains and subdomains related to a given domain
masscan - TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
gcc-poison - gcc-poison
theHarvester - E-mails, subdomains and names Harvester - OSINT
nuclei - Fast and customizable vulnerability scanner based on simple YAML based DSL.
spiderfoot - SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
stb - stb single-file public domain libraries for C/C++
cmake-lint - Fork of https://github.com/richq/cmake-lint to continue maintenance
c-smart-pointers - Smart pointers for the (GNU) C programming language
American Fuzzy Lop - american fuzzy lop - a security-oriented fuzzer