A Python3 based C2 server to make life of red teamer a bit easier. The payload is capable to bypass all the known antiviruses and endpoints.
-
Updated
Feb 5, 2024 - Python
A Python3 based C2 server to make life of red teamer a bit easier. The payload is capable to bypass all the known antiviruses and endpoints.
Postman-API-Count is a tool that simplifies the extraction and analysis of APIs from Postman collections. It allows users to extract APIs based on specific HTTP methods, identify APIs without any defined methods, and retrieve the total count of APIs in a collection. This tool is beneficial for developers and testers working with Postman collections
SCOPE [Subdomain Cache Observation, Poisoning & Evaluation] is a simple, yet powerful tool designed to help you find and test vulnerabilities in subdomains that might be exposed to cache poisoning attacks. If a website isn't properly handling cache, it could lead to security issues where malicious content gets stored and served to users.
This is a tool used by several security researchers to find Open Redirect Bug
Apache Superset - Authentication Bypass
Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal
CVE-2020-27838 - KeyCloak - Information Exposure
Web Security Audit
SAP Knowledge Warehouse <=7.5.0 - Cross-Site Scripting
Windows Server 2003 & IIS 6.0 - Remote Code Execution
This repository is a comprehensive collection of security tools designed for penetration testing, vulnerability scanning, and ethical hacking. The tools are organized into various categories, such as: XSS Injection: Tools to identify and exploit Cross-Site Scripting (XSS) vulnerabilities in web applications.
StealthWeb is a versatile cybersecurity tool designed for web analysis and security testing. Its primary functions include DNS and directory enumeration, virtual host discovery, file enumeration, and the detection of web technologies
Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery
This repository contains a Django-based API for performing basic vulnerability assessments on target web applications.
Filter out the scope IP addresses from IP address list when you have out of scope IP address list
Designed to identify 🔎 open redirect vulnerabilities🪲 which can be chained 🔗⚓ with other vulnerabilities. this tool leverages asynchronous operations that reduce scan time by 80%, significantly enhancing its eficiency.⚓⚓
Add a description, image, and links to the vapt topic page so that developers can more easily learn about it.
To associate your repository with the vapt topic, visit your repo's landing page and select "manage topics."