Gf-Patterns

Vulnerability scanner

A toolset for identifying potential security vulnerabilities and patterns in web applications

GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep

GitHub

1k stars
28 watching
280 forks
last commit: 2 months ago

Related projects:

Repository Description Stars
dustyfresh/php-vulnerability-audit-cheatsheet A collection of grep commands to help find potentially vulnerable PHP code 346
kathanp19/gaussrf A tool for identifying potential vulnerabilities in websites by fetching known URLs and filtering out ones with open redirects or SSRF parameters. 165
r0075h3ll/oralyzer A tool to identify vulnerabilities in web applications by probing for Open Redirections and other types of attacks. 753
gquere/pwn_jenkins Provides information and tools for exploiting security vulnerabilities in Jenkins servers 1,966
designsecurity/progpilot An application security testing tool for identifying vulnerabilities in PHP code 330
damian89/extended-ssrf-search An SSRF scanner written in Python to identify potential vulnerabilities by scanning predefined settings in URLs and request headers. 274
spidermate/b-xssrf A toolkit to detect and track vulnerabilities in web applications 295
eddiezab/aggressor-scripts A collection of scripts and tools for testing and exploiting network and system vulnerabilities. 1
freefv/tencent_yun_tools A collection of Python scripts to exploit vulnerabilities in Tencent Cloud services using an AccessKey 34
fkie-cad/cwe_checker Automated binary analysis tool to detect common software vulnerabilities 1,124
gand3lf/semgrepper An extension to Burp Suite that integrates Semgrep for vulnerability scanning and analysis 87
m0nad/hellraiser Scans networks to identify vulnerabilities by correlating CPEs with CVEs using an API 562
utiso/dorkbot A command-line tool to scan search results for vulnerabilities in webpages 512
jlospinoso/unfurl An entropy-based tool to identify link vulnerabilities in software 60
firefart/hijagger A tool used to identify potential security vulnerabilities in package maintainers of NPM and PyPi packages by checking for unregistered domains or email addresses. 286