Web Application Security
71 tools found
Interactsh
Tool to detect out-of-band (OOB) interactions triggered by vulnerabilities.
httpx
Fast HTTP toolkit for reliable probing using multi-threading and retryable HTTP requests.
rawhttp
Go library for sending HTTP requests with full control and minimal validation.
ffuf
Fast web fuzzer for discovering hidden files and directories in web applications.
XSStrike
XSS detection suite with parsers, intelligent payload generator, and fast crawler.
Arjun
Tool to find valid HTTP query parameters in URLs, with an extensive dictionary.
toxssin
Open-source tool for automating Cross-Site Scripting (XSS) vulnerability exploitation.
CrackQL
GraphQL pentesting tool exploiting rate-limit flaws for brute-force and fuzzing.
xray
Comprehensive web security assessment tool with vulnerability scanning and custom POC.
sqlmap
Open-source tool to automate SQL injection detection and exploitation in databases.
bwapp
Deliberately insecure web application with over 100 bugs for vulnerability learning.
DVWA
Intentionally vulnerable PHP/MariaDB web application for security testing and learning.
Request Map Generator
Generates a request map for a page to identify third parties, byte origin, and slowness.
IP Rotate
Burp Suite extension changing IP per request via AWS API Gateway to bypass blocking.
sandcat
Lightweight, fast browser with pen-testing/web development features, extensible via Lua.
WATOBO
Security tool for efficient (semi-automated) web application security audits.
Weevely
Web shell for post-exploitation with over 30 modules for admin tasks and access.
AuthMatrix
Burp extension to test permissions and access controls in web applications.
backslash
Burp extension for detecting server-side injections with evasive, precise techniques.
Agartha
Generates payloads and assesses LFI, RCE, SQLi, auth, and access bypass issues.
Freddy
Burp Suite extension for finding and exploiting serialization vulnerabilities.