All In One Web Recon
-
Updated
Jun 1, 2026 - Python
All In One Web Recon
Find S3 AWS/GCP/Azure buckets while surfing. S3DNS acts as DNS server, follows CNAMEs and matches any bucket pattern
Advanced CORS Header Checker Tool with Vulnerability Detection and Bypass Attempts
Web Path Finder
This course uses a deliberately vulnerable banking application to demonstrate common security vulnerabilities, their impact, and how to fix them. The application is built with Flask (backend) and React (frontend).
Whitepass Bypass Whitelist/Ratelimit Implementations in Web Applications/APIs
The CyberTalents repository is a collection of solutions and write-ups for challenges sourced from the CyberTalents platform. Organized topic, this repository serves as a resource for cybersecurity enthusiasts seeking to enhance their skills and understanding of security concepts.
Small tool to decode ASP.NET __VIEWSTATE variable when doing webpentests
A powerful recon tool
Lightweight Python reconnaissance scanner for service fingerprinting, subdomain discovery, web vulnerabilities, and security misconfigurations
The simplest way to integrate your subdomain enum outputs with Burp Pro (Fast Crawler)
This extension allows you to detect implementations of postMessage function, addEventListener("message",function) event handler and onMessage function.
Erlik 2 - Vulnerable-Flask-App
web application penetration testing and security notes.
jsonAnalytic - List all keys & all values in json
🔧 A simple but powerful CLI-based toolkit for basic reconnaissance — includes subdomain discovery, header scanning, port scanning, etc.
Admin Finder Tool is a Python-based tool designed to help security professionals, penetration testers, and website administrators identify potentially sensitive admin areas on a website. The tool works by testing a list of common admin URL paths and checking if any of these return a 200 HTTP status code, indicating that they exist.
A Next-Generation AI-Powered Vulnerability Scanner & Hardening Assistant designed for modern defensive security research. It combines web crawling, dynamic analysis, and powerful AI reasoning to uncover logical flaws, insecure patterns, and weak configurations.
A collaborative repository for web pentesting notes and tool commands. Contribute your knowledge to build a comprehensive resource for Web pentester, Bug bounty hunter, Ethical hacker and security professionals.
Add a description, image, and links to the webpentest topic page so that developers can more easily learn about it.
To associate your repository with the webpentest topic, visit your repo's landing page and select "manage topics."