ppmap
dalfox
ppmap | dalfox | |
---|---|---|
3 | 1 | |
446 | 3,298 | |
- | - | |
0.0 | 8.5 | |
almost 2 years ago | 15 days ago | |
Go | Go | |
GNU General Public License v3.0 only | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
ppmap
- How do I get the ppmap to fuzz test vulerable website with custom xss json payload to exploit client side prototype pollution cross site script?
- How do I get the ppmap to fuzz test vulerable website with custom xss json payload to exploit prototype pollution cross site script?
- A simple scanner/exploitation tool written in GO which automatically exploits known and existing gadgets (checks for specific variables in the global context) to perform XSS via Prototype Pollution.
dalfox
-
xss waf bypass
Dalfox is great: https://github.com/hahwul/dalfox
What are some alternatives?
ppfuzz - A fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀
XSStrike - Most advanced XSS scanner.
hetty - An HTTP toolkit for security research.
tomcat-jmxproxy-rce-exp - Apache Tomcat JMXProxy RCE
interactsh - An OOB interaction gathering server and client library
go-dork - The fastest dork scanner written in Go.
Awesome-WAF - 🔥 Web-application firewalls (WAFs) from security standpoint.
urlhunter - a recon tool that allows searching on URLs that are exposed via shortener services
PassDetective - PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords, API keys, and secrets. Using regular expressions, it helps prevent accidental exposure of sensitive information in your command history.
xss-payload-list - 🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List