You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
🧿 AutorizePro是一款强大越权检测 Burp 插件,通过增加 AI 辅助分析 && 进一步优化检测逻辑,大幅降低误报率,提升越权漏洞检出效率。 [ AutorizePro is a authorization enforcement detection extension for burp suite. By adding Ai-assisted analysis, it significantly reduces the false positive rate and improves the efficiency of vulnerability detection.
✅ Experience the power of an automated Insecure Direct Object Reference (IDOR) vulnerability detection tool. Safeguard your applications with cutting-edge technology that identifies potential security weaknesses in an efficient and streamlined manner.
A lightweight, high-performance browser extension (Manifest V3) designed for penetration testers and ethical hackers. Features passive HTTP traffic inspection, automated IDOR/BOLA scoring, noise filtering, and AI-driven vulnerability analysis with PDF report generation. Built for ethical security research.
The "Web Security Scripts" repository is a curated collection of Python scripts meticulously crafted by Tejas Barguje Patil to fortify website security. From scanning for critical vulnerabilities such as SQL injection and XSS to investigating subdomains for potential risks, these tools provide a comprehensive toolkit for web developers and security
This project is a deliberately vulnerable web application developed using PHP and MySQL. It is designed for learning, demonstration, and testing of web application security vulnerabilities and secure coding practices.
A hands-on web application penetration testing lab based on OWASP Juice Shop, covering the OWASP Top 10 vulnerabilities. Includes practical testing methodology, Burp Suite workflows, vulnerability analysis, CVSS scoring, and professional reporting.
A comprehensive collection of Capture The Flag (CTF) writeups, vulnerability assessments, and web exploitation methodologies. This repository documents my step-by-step approach to solving complex cybersecurity challenges, focusing on identifying and exploiting logic flaws, IDOR, SQLi, and XSS vulnerabilities.
Before/after security hardening of an AI-generated Supabase SaaS. 19 findings: service-role key in the browser, no row level security, broken object-level authorization, public storage bucket. Exploit tests on both branches, demonstrating each hole then proving it closed.