dalfox
go-dork
Our great sponsors
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
dalfox
-
xss waf bypass
Dalfox is great: https://github.com/hahwul/dalfox
go-dork
What are some alternatives?
XSStrike - Most advanced XSS scanner.
dorkscout - DorkScout - Golang tool to automate google dork scan against the entiere internet or specific targets
tomcat-jmxproxy-rce-exp - Apache Tomcat JMXProxy RCE
interactsh - An OOB interaction gathering server and client library
ppmap - A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.
pagodo - pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching
Awesome-WAF - 🔥 Web-application firewalls (WAFs) from security standpoint.
PassDetective - PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords, API keys, and secrets. Using regular expressions, it helps prevent accidental exposure of sensitive information in your command history.
EDRHunt - Scan installed EDRs and AVs on Windows
ppfuzz - A fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀
urlhunter - a recon tool that allows searching on URLs that are exposed via shortener services