GitHub repo leaderboard by stars, growth rate and activity.
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
🐶 A curated list of Web Security materials and resources.
Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。
Useful Google Dorks for WebSecurity and Bug Bounty
Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.
Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.
一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能
Anonymous automation with fingerprint replacement technology.
| # | Repo | Language | Stars | 30-day trend | Last updated |
|---|---|---|---|---|---|
| 1 | SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits. | Go | 22,549 | last pushed 1 week ago | |
| 2 | 🐶 A curated list of Web Security materials and resources. | Python | 13,781 | last pushed 5 days ago | |
| 3 | Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。 | Shell | 2,073 | last pushed 3 years ago | |
| 4 | Useful Google Dorks for WebSecurity and Bug Bounty | — | 1,370 | last pushed 2 months ago | |
| 5 | Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests. | Rust | 1,236 | last pushed 2 years ago | |
| 6 | Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust. | Rust | 1,081 | last pushed 4 weeks ago | |
| 7 | An HTTP/HTTPS intercept proxy written in Go. | Go | 1,008 | last pushed 5 years ago | |
| 8 | Bug Bounty Tricks and useful payloads and bypasses for Web Application Security. | — | 806 | last pushed 3 weeks ago | |
| 9 | 一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能 | Python | 644 | last pushed 7 years ago | |
| 10 | Anonymous automation with fingerprint replacement technology. | JavaScript | 245 | last pushed 5 months ago |
All · 11,474