WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress installations and other content management systems. It functions as a web application security tool that identifies misconfigurations, outdated software, and security holes in core installations, plugins, and themes. The tool employs black-box scanning techniques to perform site component enumeration, identifying users, themes, and plugins by matching known file paths and response signatures. It matches these detected components against a database of known security flaws to analyze the
A tool for bug hunting or pentesting for targeting websites that have open .git repositories available in public
Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.
Scriptable network authentication cracker
Les fonctionnalités principales de kpcyrd/badtouch sont : Web Security Tools.
Les alternatives open-source à kpcyrd/badtouch incluent : wpscanteam/wpscan — WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress… codingo/vhostscan — A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work… hightechsec/git-scanner — A tool for bug hunting or pentesting for targeting websites that have open .git repositories available in public. nil0x42/phpsploit — Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor. owasp/nodegoat — The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications… spectralops/keyscope — Keyscope is a key and secret workflow (validation, invalidation, etc.) tool built in Rust.