mitmproxy by mitmproxy

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

created at Feb. 16, 2010, 4:10 a.m.

Python

622 +0

34,515 +77

3,907 +6

GitHub
DVCS-Pillage by evilpacket

Pillage web accessible GIT, HG and BZR repositories

created at June 18, 2011, 8:04 p.m.

Shell

16 +0

313 +0

63 +0

GitHub
beef by beefproject

The Browser Exploitation Framework Project

created at Nov. 23, 2011, 6:53 a.m.

JavaScript

438 -1

9,406 +10

2,060 +1

GitHub
sqlmap by sqlmapproject

Automatic SQL injection and database takeover tool

created at June 26, 2012, 9:52 a.m.

Python

1,090 +1

30,690 +56

5,549 +11

GitHub
radare2 by radareorg

UNIX-like reverse engineering framework and command-line toolset

created at July 3, 2012, 7:42 a.m.

C

483 -2

19,678 +20

2,938 +1

GitHub
wpscan by wpscanteam

WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com

created at July 11, 2012, 8:27 p.m.

Ruby

264 +0

8,258 +7

1,240 +4

GitHub
js-xss by leizongmin

Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist

created at Sept. 18, 2012, 2:05 p.m.

HTML

117 +0

5,107 +1

630 +0

GitHub
dvcs-ripper by kost

Rip web accessible (distributed) version control systems: SVN/GIT/HG...

created at Oct. 23, 2012, 4:55 a.m.

Perl

52 -1

1,648 +1

308 +0

GitHub
webshell by tennc

This is a webshell open source project

created at May 23, 2013, 7:37 a.m.

PHP

490 -2

9,791 +4

5,552 +4

GitHub
retire.js by RetireJS

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

created at Aug. 30, 2013, 9:43 p.m.

JavaScript

86 -1

3,529 +6

412 +0

GitHub
DOMPurify by cure53

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

created at Feb. 17, 2014, 9:48 p.m.

JavaScript

150 -2

12,924 +54

670 -1

GitHub
EyeWitness by RedSiege

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

created at Feb. 26, 2014, 4:23 p.m.

Python

147 +0

4,715 +4

819 +0

GitHub
H5SC by cure53

HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors

created at March 28, 2014, 8:42 a.m.

JavaScript

153 -1

2,820 -2

418 +0

GitHub
certificate-transparency by google

Auditing for TLS certificates.

created at May 20, 2014, 5:03 p.m.

C++

103 +0

866 +0

282 +0

GitHub
phpsploit by nil0x42

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

created at May 21, 2014, 7:43 p.m.

Python

103 +0

2,146 +7

434 +1

GitHub
Infosec_Reference by rmusser01

An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.

created at Sept. 13, 2014, 12:08 a.m.

CSS

266 -1

5,363 +1

1,178 -2

GitHub
juice-shop by juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

created at Sept. 19, 2014, 2:53 p.m.

TypeScript

156 +0

9,589 +31

9,399 +50

GitHub
weevely3 by epinna

Weaponized web shell

created at Sept. 20, 2014, 10:16 a.m.

Python

132 +1

3,077 +2

596 +0

GitHub
wfuzz by xmendez

Web application fuzzer

created at Oct. 22, 2014, 9:23 p.m.

Python

168 +0

5,663 +9

1,332 +1

GitHub
gitrob by michenriksen

Reconnaissance tool for GitHub organizations

created at Jan. 7, 2015, 1:58 p.m.

Go

154 +0

5,839 +2

823 +0

GitHub