off-by-slash

URL generator and tester

Automatically detects alias traversal vulnerabilities in NGINX configurations by generating and testing malicious URLs.

Burp extension to detect alias traversal via NGINX misconfiguration at scale.

GitHub

254 stars
7 watching
36 forks
Language: Python
last commit: almost 5 years ago
Linked from 1 awesome list

burpsuitenginxpath-traversal

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
xnl-h4ck3r/gap-burp-extensionAn extension for Burp Suite that identifies potential security vulnerabilities in web applications by analyzing endpoints, parameters, and generating custom target wordlists.1,278
initroot/burpsqltruncsannerAutomatically scans endpoints for potential SQL Truncation vulnerabilities by fuzzing request parameters62
gauravnarwani97/trishulAutomated vulnerability detection tool for web applications235
attackercan/burp-xss-sql-pluginAutomated tool for detecting cross-site scripting (XSS) and SQL injection vulnerabilities in web applications.44
momenbasel/liffierAutomatically appends dot-dot-slash to URLs to test for path traversal vulnerabilities.8
vulnerscom/burp-vulners-scannerA tool that searches for vulnerabilities in web applications using an external API838
p3gleg/pwnbackGenerates a sitemap of a website using Wayback Machine225
wagiro/burpbountyA tool that allows users to enhance and customize the vulnerability scanning capabilities of Burp Suite using a graphical interface.1,685
codewatchorg/burp-indicatorsofvulnerabilityA Burp extension that scans application traffic for signs of vulnerabilities and potential attack targets41
1n3/intruderpayloadsA collection of tools and methodologies for identifying vulnerabilities in web applications3,698
bugcrowd/huntAn extension for Burp Suite that provides a structured approach to identifying and testing common vulnerability parameters.2,192
yg-ht/burp-lookoverthereA Burp Suite extension to enhance scanning by injecting HTTP redirects into responses from specific APIs.0
portswigger/backslash-powered-scannerAn extension for Burp Suite that scans for unknown classes of injection vulnerabilities using a novel approach643
h3xstream/burp-retire-jsA tool that integrates with Burp and ZAP to identify vulnerable JavaScript libraries200
nccgroup/argumentinjectionhammerAn extension that identifies argument injection vulnerabilities in web applications using payloads and detection techniques118