Web Technologies
This page tracks security notes and tools for common web platforms, frameworks, identity technologies, APIs, and CMSs. Keep passive domain discovery in Cyber Intelligence, O365 spraying in Password Attacks, and malware/API cheat sheets in DFIR or exploit-development pages.
Adobe AEM
aem-hacker - Tools to identify vulnerable Adobe Experience Manager (AEM) webapps.
aemscan - Adobe Experience Manager Vulnerability Scanner
Apache Web Server
apache-users - This Perl script will enumerate the usernames on any system that uses Apache with the UserDir modul
APIs
OWASP API Security Top 10 - Use the current project page rather than only the older 2019 PDF.
https://gist.github.com/yassineaboukir/8e12adefbd505ef704674ad6ad48743d - API Endpoint wordlist
imperva/automatic-api-attack-tool - Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.
Astra - Automated Security Testing For REST API's
OWASP API check - APICheck is an environment for integrating existing HTTP APIs tools and create execution chains easily.
VX-API - Windows API tricks and malware-oriented API notes. This is not a web API resource; keep here only as a pointer for API terminology overlap.
malapi.io - Windows API reference for malware behavior. Better fit for malware/reverse engineering workflows.
crAPI - completely ridiculous API (crAPI) will help you to understand the ten most critical API security risks. crAPI is vulnerable by design, but you'll be able to safely run it to educate/train yourself.
https://github.com/Net-hunter121/API-Wordlist - A wordlist of API names used for fuzzing web application APIs.
https://github.com/metlo-labs/metlo - Metlo is an open-source API security platform
Hacking: The next generation - Application Protocol Handlers, pg. 96
For training on APIs and API hacking, please see https://github.com/jassics/security-study-plan/blob/main/api-security-study-plan.md.
ASP.NET
viewgen - a ViewState tool capable of generating both signed and encrypted payloads with leaked validation keys
Cloudflare
cloudflare_enum - Cloudflare DNS enumeration tool. Passive DNS/domain investigation belongs in Cyber Intelligence.
Firebase
Firebase
Insecure-Firebase-Exploit - A simple Python Exploit to Write Data to Insecure/vulnerable firebase databases! Commonly found inside Mobile Apps. If the owner of the app have set the security rules as true for both "read" & "write" an attacker can probably dump database and write his own data to firebase db.
Firebase-Extractor - A tool written in python for scraping firebase data
Pyrebase - A simple python wrapper for the Firebase API.
Flask
Flask-Unsign - Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.
Google Web Toolkit
GWTMap - GWTMap is a tool to help map the attack surface of Google Web Toolkit (GWT) based applications.
.htaccess File
htshells - htshells is a series of web based attacks based around the .htaccess files. Most of the attacks are centered around two attack categories. Remote code/ command execution and information disclosure.
JavaScript
JSScanner - Scan JS Files for Endpoints and Secrets
JSFScan.sh - Automation for javascript recon in bug bounty.
jshole - A JavaScript components vulnerability scanner, based on RetireJS
Retire.JS - Burp/ZAP/Maven extension that integrate Retire.js repository to find vulnerable Javascript libraries.
JSshell - JavaScript reverse/remote shell from XSS
unmap - Unpack a JavaScript Source Map back into filesystem structure
JSA - Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.
JBoss
jboss-autopwn - This JBoss script deploys a JSP shell on the target JBoss AS server. Once deployed, the script uses its upload and command execution capability to provide an interactive session.
jexboss - JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool
Jenkins
pwn_jenkins - Notes about attacking Jenkins servers
Accenture/jenkins-attack-framework - Project for enumerating and attacking Jenkins.
Jira
jira_scan - A simple remote scanner for Atlassian Jira
Joomla
JCS - JCS (Joomla Component Scanner) made for penetration testing purpose on Joomla CMS
Joomscan - OWASP Joomla! Vulnerability Scanner (JoomScan) is an open source project, developed with the aim of automating the task of vulnerability detection and reliability assurance in Joomla CMS deployments.
juumla - Juumla is a python tool created to identify Joomla version, scan for vulnerabilities and search for config files.
Magento
magescan - Scan a Magento site for information
NGINX
nginxpwner - Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.
OneLogin - SAML
SAMLExtractor - A tool that can take a URL or list of URL and prints back SAML consume URL.ex
OWA/O365
Microsoft 365 username enumeration, spraying, and mailbox search tooling is maintained with Password Attacks and Cloud. The links below are kept here only because OWA is a web-facing technology.
MailSniper - MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
byt3bl33d3r/SprayingToolkit - Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient
o365enum - Enumerate valid usernames from Office 365 using ActiveSync, Autodiscover v1, or office.com login page.
o365-attack-toolkit - o365-attack-toolkit allows operators to perform oauth phishing attacks.
http://www.blackhillsinfosec.com/?p=4694 - UserName Recon/Password Spraying
http://www.blackhillsinfosec.com/?p=5089 - Password Spraying MFA/2FA
http://www.blackhillsinfosec.com/?p=5330 - Password Spraying/GlobalAddressList
http://www.blackhillsinfosec.com/?p=5396 - Outlook 2FA Bypass
https://silentbreaksecurity.com/malicious-outlook-rules/ - Malicious Outlook Rules
http://www.blackhillsinfosec.com/?p=5465 - Outlook Rules in Action
Ruby on Rails
brakeman - A static analysis security vulnerability scanner for Ruby on Rails applications
SAP
SAP_RECON - PoC for CVE-2020-6287, CVE-2020-6286 (SAP RECON vulnerability)
Virtual Hosts
virtual-host-discovery - A script to enumerate virtual hosts on a server.
vhosts-sieve - Searching for virtual hosts among non-resolvable domains
VHostScan - A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.ex
Web Proxies
https://github.com/GrrrDog/weird_proxies - Reverse proxies cheatsheet
Wordpress - Resources
WPScan - The Wordpress Vulnerability Scanner
https://wpsec.com/ - Online Wordpress scanner
Wordpress Exploit Framework - A Ruby framework designed to aid in the penetration testing of WordPress systems.
WPSploit - This repository is designed for creating and/or porting of specific exploits for WordPress using metasploit as exploitation tool.
xmlrpc-scan - Scan urls or a single URL against XMLRPC wordpress issues.
wpxploit - Simple Python Script For Performing XMLRPC Dictionary Attack
plecost - Wordpress finger printer tool, plecost search and retrieve information about the plugins versions installed in Wordpress systems.
WordPress Common Bugs
Denial of Service via load-scripts.php
Denial of Service via load-styles.php
Log files exposed
Backup file wp-config exposed
Information disclosure wordpress username
Bruteforce in wp-login.php
XSPA in wordpress
Source: https://github.com/daffainfo/AllAboutBugBounty/blob/master/CMS/WordPress.md
Last updated