awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to 0xinfection/xsrfprobe

Projects sharing features with XSRFProbe

24 open-source projects similar to 0xinfection/xsrfprobe, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • aleff-github/wayparamaleff-github avatar

    aleff-github/wayparam

    6View on GitHub↗

    Fetch and normalize parameterized URLs from the Wayback CDX API (OSINT, inspired by ParamSpider).

    Python
    View on GitHub↗6
  • beefproject/beefbeefproject avatar

    beefproject/beef

    10,728View on GitHub↗

    BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and

    JavaScript
    View on GitHub↗10,728
  • ben-lichtman/roprB

    Ben-Lichtman/ropr

    0View on GitHub↗
    View on GitHub↗0
  • bo0om/fuzz.txtBo0oM avatar

    Bo0oM/fuzz.txt

    3,312View on GitHub↗

    Potentially dangerous files

    View on GitHub↗3,312
  • commixproject/commixcommixproject avatar

    commixproject/commix

    5,757View on GitHub↗

    Commix is an automated tool for detecting and exploiting OS command injection vulnerabilities in web applications. It probes user-supplied input vectors with heuristic test payloads, analyzes response differences to identify injection points, and then automates the execution of arbitrary operating system commands on the target server. The tool distinguishes itself through a multi-layer filter bypass engine that evaluates input constraints independently per filter type and composes tailored evasion strategies into a single payload. A modular payload tamper pipeline transforms raw injection str

    Python
    View on GitHub↗5,757

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • enjoiz/xxeinjectorenjoiz avatar

    enjoiz/XXEinjector

    1,754View on GitHub↗

    Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.

    Ruby
    View on GitHub↗1,754
  • epinna/tplmapepinna avatar

    epinna/tplmap

    4,169View on GitHub↗

    tplmap is a security tool designed for the detection and exploitation of server-side template injection vulnerabilities. It functions as an automated scanner to identify vulnerable template engine contexts and provides a framework for achieving remote code execution. The tool focuses on translating high-level requests into engine-specific syntax to execute operating system commands and bypass application sandboxes. It further enables remote file system access, allowing users to read, write, and transfer files between a local machine and a target server. Additional capabilities include the ab

    Python
    View on GitHub↗4,169
  • fuzzdb-project/fuzzdbfuzzdb-project avatar

    fuzzdb-project/fuzzdb

    8,819View on GitHub↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    PHP
    View on GitHub↗8,819
  • google/domatogoogle avatar

    google/domato

    1,784View on GitHub↗

    DOM fuzzer

    Python
    View on GitHub↗1,784
  • gosecure/dtd-finderGoSecure avatar

    GoSecure/dtd-finder

    661View on GitHub↗

    List DTDs and generate XXE payloads using those local DTDs.

    Kotlin
    View on GitHub↗661
  • hack-all-the-things/charsetinspecthack-all-the-things avatar

    hack-all-the-things/charsetinspect

    28View on GitHub↗

    A script that inspects multi-byte character sets looking for characters with specific user-defined properties

    Python
    View on GitHub↗28
  • luisfontes19/xxexploiterluisfontes19 avatar

    luisfontes19/xxexploiter

    608View on GitHub↗

    Tool to help exploit XXE vulnerabilities

    TypeScript
    View on GitHub↗608
  • mzfr/liffymzfr avatar

    mzfr/liffy

    968View on GitHub↗

    Local file inclusion exploitation tool

    Python
    View on GitHub↗968
  • nccgroup/singularitynccgroup avatar

    nccgroup/singularity

    1,301View on GitHub↗

    A DNS rebinding attack framework.

    JavaScript
    View on GitHub↗1,301
  • nekmo/dirhuntNekmo avatar

    Nekmo/dirhunt

    2,004View on GitHub↗

    Find web directories without bruteforce

    Python
    View on GitHub↗2,004
  • nickstadb/barmieNickstaDB avatar

    NickstaDB/BaRMIe

    748View on GitHub↗

    BaRMIe is a tool for enumerating and attacking Java RMI (Remote Method Invocation) services.

    Java
    View on GitHub↗748
  • osandamalith/ipobfuscatorOsandaMalith avatar

    OsandaMalith/IPObfuscator

    145View on GitHub↗

    A simple tool to convert the IP to a DWORD IP

    C
    View on GitHub↗145
  • r0oth3x49/ghaurir0oth3x49 avatar

    r0oth3x49/ghauri

    4,032View on GitHub↗

    Ghauri is an automated SQL injection scanner and exploitation tool designed to detect and extract data from vulnerable databases. It functions as a database exfiltration framework that identifies security flaws and retrieves system banners, hostnames, and database schemas. The tool identifies boolean, error, time-based, and stacked query vulnerabilities across multiple input vectors, including HTTP headers, cookies, JSON, SOAP, and XML. It provides capabilities for automated database exfiltration and the processing of bulk target lists to identify flaws across multiple environments. The syst

    Python
    View on GitHub↗4,032
  • sqlmapproject/sqlmapsqlmapproject avatar

    sqlmapproject/sqlmap

    37,676View on GitHub↗

    This project is an automated security testing suite designed to detect and exploit database vulnerabilities. It functions as a command-line utility that streamlines the identification, verification, and exploitation of web application flaws by automating the injection of malicious payloads into input parameters. The tool provides a comprehensive framework for database enumeration, allowing users to extract schema information, user data, and system configurations from identified injection points. What distinguishes this tool is its sophisticated engine for dynamic payload adaptation and heuris

    Pythondatabasedetectionexploitation
    View on GitHub↗37,676
  • staaldraad/xxeservstaaldraad avatar

    staaldraad/xxeserv

    344View on GitHub↗

    A mini webserver with FTP support for XXE payloads

    Go
    View on GitHub↗344
  • t3l3machus/toxssint3l3machus avatar

    t3l3machus/toxssin

    1,432View on GitHub↗

    An XSS exploitation command-line interface and payload generator.

    Pythoncross-site-scriptingexploitationhacking
    View on GitHub↗1,432
  • tarunkant/gopherustarunkant avatar

    tarunkant/Gopherus

    3,386View on GitHub↗

    This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

    Python
    View on GitHub↗3,386
  • trufflesecurity/of-corsT

    trufflesecurity/of-CORS

    0View on GitHub↗
    View on GitHub↗0
  • xmendez/wfuzzxmendez avatar

    xmendez/wfuzz

    6,519View on GitHub↗

    Wfuzz is a web application fuzzing framework that automates the injection of payloads into HTTP requests to discover hidden resources, parameters, and vulnerabilities. It functions as a content discovery scanner, a brute-force tool for credential guessing, and a plugin-based vulnerability scanner, all within a single modular system. The tool distinguishes itself through its plugin-based extensibility, allowing custom Python modules to add new payload sources, output printers, or scanning logic without modifying core code. It supports concurrent request dispatch using thread-based parallelism

    Python
    View on GitHub↗6,519