diff --git a/README.md b/README.md index 42d562d..9b17a57 100644 --- a/README.md +++ b/README.md @@ -12,7 +12,7 @@ A collection of cool tools used by Web hackers. Happy hacking , Happy bug-huntin - [Subdomain Enumeration](#subdomain-enumeration) - [Fetch path and host](#fetch-path-and-host) - [Port scanner](#port-scanner) - - [Web Crawler](#web-crawler) + - [Web Discovery](#web-discovery) - [Web Vulnerability Scanner](#web-vulnerability-scanner) - [XSS](#xss) - [CSRF](#csrf) @@ -30,9 +30,39 @@ A collection of cool tools used by Web hackers. Happy hacking , Happy bug-huntin ## Weapons ### Subdomain Enumeration + +| Name | Description | Popularity | Language | Metadata | +| ---------- | :---------- | :----------: | :----------: | :----------: | +| [findomain](https://github.com/Edu4rdSHL/findomain) | The fastest and cross-platform subdomain enumerator, do not waste your time. | ![](https://img.shields.io/github/stars/Edu4rdSHL/findomain) | ![](https://img.shields.io/github/languages/top/Edu4rdSHL/findomain) | ![](https://img.shields.io/github/repo-size/Edu4rdSHL/findomain)
![](https://img.shields.io/github/license/Edu4rdSHL/findomain)
![](https://img.shields.io/github/forks/Edu4rdSHL/findomain)
![](https://img.shields.io/github/watchers/Edu4rdSHL/findomain) | +| [subfinder](https://github.com/projectdiscovery/subfinder) | Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing. | ![](https://img.shields.io/github/stars/projectdiscovery/subfinder) | ![](https://img.shields.io/github/languages/top/projectdiscovery/subfinder) | ![](https://img.shields.io/github/repo-size/projectdiscovery/subfinder)
![](https://img.shields.io/github/license/projectdiscovery/subfinder)
![](https://img.shields.io/github/forks/projectdiscovery/subfinder)
![](https://img.shields.io/github/watchers/projectdiscovery/subfinder) | +| [Amass](https://github.com/OWASP/Amass) | In-depth Attack Surface Mapping and Asset Discovery | ![](https://img.shields.io/github/stars/OWASP/Amass) | ![](https://img.shields.io/github/languages/top/OWASP/Amass) | ![](https://img.shields.io/github/repo-size/OWASP/Amass)
![](https://img.shields.io/github/license/OWASP/Amass)
![](https://img.shields.io/github/forks/OWASP/Amass)
![](https://img.shields.io/github/watchers/OWASP/Amass) | +| [Sublist3r](https://github.com/aboul3la/Sublist3r) | Fast subdomains enumeration tool for penetration testers | ![](https://img.shields.io/github/stars/aboul3la/Sublist3r) | ![](https://img.shields.io/github/languages/top/aboul3la/Sublist3r) | ![](https://img.shields.io/github/repo-size/aboul3la/Sublist3r)
![](https://img.shields.io/github/license/aboul3la/Sublist3r)
![](https://img.shields.io/github/forks/aboul3la/Sublist3r)
![](https://img.shields.io/github/watchers/aboul3la/Sublist3r) | +| [assetfinder](https://github.com/tomnomnom/assetfinder) | Find domains and subdomains related to a given domain | ![](https://img.shields.io/github/stars/tomnomnom/assetfinder) | ![](https://img.shields.io/github/languages/top/tomnomnom/assetfinder) | ![](https://img.shields.io/github/repo-size/tomnomnom/assetfinder)
![](https://img.shields.io/github/license/tomnomnom/assetfinder)
![](https://img.shields.io/github/forks/tomnomnom/assetfinder)
![](https://img.shields.io/github/watchers/tomnomnom/assetfinder) | + ### Fetch path and host + +| Name | Description | Popularity | Language | Metadata | +| ---------- | :---------- | :----------: | :----------: | :----------: | +| [meg](https://github.com/tomnomnom/meg) | Fetch many paths for many hosts - without killing the hosts | ![](https://img.shields.io/github/stars/tomnomnom/meg) | ![](https://img.shields.io/github/languages/top/tomnomnom/meg) | ![](https://img.shields.io/github/repo-size/tomnomnom/meg)
![](https://img.shields.io/github/license/tomnomnom/meg)
![](https://img.shields.io/github/forks/tomnomnom/meg)
![](https://img.shields.io/github/watchers/tomnomnom/meg) | +| [httprobe](https://github.com/tomnomnom/httprobe) | Take a list of domains and probe for working HTTP and HTTPS servers | ![](https://img.shields.io/github/stars/tomnomnom/httprobe) | ![](https://img.shields.io/github/languages/top/tomnomnom/httprobe) | ![](https://img.shields.io/github/repo-size/tomnomnom/httprobe)
![](https://img.shields.io/github/license/tomnomnom/httprobe)
![](https://img.shields.io/github/forks/tomnomnom/httprobe)
![](https://img.shields.io/github/watchers/tomnomnom/httprobe) | + ### Port scanner -### Web Crawler + +| Name | Description | Popularity | Language | Metadata | +| ---------- | :---------- | :----------: | :----------: | :----------: | +| [nmap](https://github.com/nmap/nmap) | Nmap - the Network Mapper. Github mirror of official SVN repository. | ![](https://img.shields.io/github/stars/nmap/nmap) | ![](https://img.shields.io/github/languages/top/nmap/nmap) | ![](https://img.shields.io/github/repo-size/nmap/nmap)
![](https://img.shields.io/github/license/nmap/nmap)
![](https://img.shields.io/github/forks/nmap/nmap)
![](https://img.shields.io/github/watchers/nmap/nmap) | +| [naabu](https://github.com/projectdiscovery/naabu) | A fast port scanner written in go with focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests | ![](https://img.shields.io/github/stars/projectdiscovery/naabu) | ![](https://img.shields.io/github/languages/top/projectdiscovery/naabu) | ![](https://img.shields.io/github/repo-size/projectdiscovery/naabu)
![](https://img.shields.io/github/license/projectdiscovery/naabu)
![](https://img.shields.io/github/forks/projectdiscovery/naabu)
![](https://img.shields.io/github/watchers/projectdiscovery/naabu) | +| [masscan](https://github.com/robertdavidgraham/masscan) | TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes. | ![](https://img.shields.io/github/stars/robertdavidgraham/masscan) | ![](https://img.shields.io/github/languages/top/robertdavidgraham/masscan) | ![](https://img.shields.io/github/repo-size/robertdavidgraham/masscan)
![](https://img.shields.io/github/license/robertdavidgraham/masscan)
![](https://img.shields.io/github/forks/robertdavidgraham/masscan)
![](https://img.shields.io/github/watchers/robertdavidgraham/masscan) | + +### Web Discovery + +| Name | Description | Popularity | Language | Metadata | +| ---------- | :---------- | :----------: | :----------: | :----------: | +| [gospider](https://github.com/jaeles-project/gospider) | Gospider - Fast web spider written in Go | ![](https://img.shields.io/github/stars/jaeles-project/gospider) | ![](https://img.shields.io/github/languages/top/jaeles-project/gospider) | ![](https://img.shields.io/github/repo-size/jaeles-project/gospider)
![](https://img.shields.io/github/license/jaeles-project/gospider)
![](https://img.shields.io/github/forks/jaeles-project/gospider)
![](https://img.shields.io/github/watchers/jaeles-project/gospider) | +| [gobuster](https://github.com/OJ/gobuster) | Directory/File, DNS and VHost busting tool written in Go | ![](https://img.shields.io/github/stars/OJ/gobuster) | ![](https://img.shields.io/github/languages/top/OJ/gobuster) | ![](https://img.shields.io/github/repo-size/OJ/gobuster)
![](https://img.shields.io/github/license/OJ/gobuster)
![](https://img.shields.io/github/forks/OJ/gobuster)
![](https://img.shields.io/github/watchers/OJ/gobuster) | +| [LinkFinder](https://github.com/GerbenJavado/LinkFinder) | A python script that finds endpoints in JavaScript files | ![](https://img.shields.io/github/stars/GerbenJavado/LinkFinder) | ![](https://img.shields.io/github/languages/top/GerbenJavado/LinkFinder) | ![](https://img.shields.io/github/repo-size/GerbenJavado/LinkFinder)
![](https://img.shields.io/github/license/GerbenJavado/LinkFinder)
![](https://img.shields.io/github/forks/GerbenJavado/LinkFinder)
![](https://img.shields.io/github/watchers/GerbenJavado/LinkFinder) | +| [wfuzz](https://github.com/xmendez/wfuzz) | Web application fuzzer | ![](https://img.shields.io/github/stars/xmendez/wfuzz) | ![](https://img.shields.io/github/languages/top/xmendez/wfuzz) | ![](https://img.shields.io/github/repo-size/xmendez/wfuzz)
![](https://img.shields.io/github/license/xmendez/wfuzz)
![](https://img.shields.io/github/forks/xmendez/wfuzz)
![](https://img.shields.io/github/watchers/xmendez/wfuzz) | + ### Web Vulnerability Scanner ### XSS ### CSRF