![](/assets/headers/header-logo.png)

![](https://img.shields.io/badge/Tools%20%26%20Resources%20Available-17-757575?style=for-the-badge)

### CORS

* [Corsy](https://github.com/s0md3v/Corsy) - CORS Misconfiguration Scanner. ![last-commit](https://img.shields.io/github/last-commit/s0md3v/Corsy?style=flat)

### Cross-Site Scripting

* [XSS'OR](https://github.com/evilcos/xssor2) - XSS'OR - Hack with JavaScript. ![last-commit](https://img.shields.io/github/last-commit/evilcos/xssor2?style=flat)
* [XSStrike](https://github.com/s0md3v/XSStrike) - Most advanced XSS scanner. ![last-commit](https://img.shields.io/github/last-commit/evilcos/xssor2?style=flat)

### CRLF

* [CRLFSuite](https://github.com/Nefcore/CRLFsuite) - The most powerful CRLF injection (HTTP Response Splitting) scanner. ![last-commit](https://img.shields.io/github/last-commit/Nefcore/CRLFsuite?style=flat)

### CSRF

* [Bolt](https://github.com/s0md3v/Bolt) - CSRF Scanner. ![last-commit](https://img.shields.io/github/last-commit/s0md3v/Bolt?style=flat)

### Databases

* [sql-map](https://github.com/sqlmapproject/sqlmap) - Automatic SQL injection and database takeover tool. ![last-commit](https://img.shields.io/github/last-commit/sqlmapproject/sqlmap?style=flat)

### Directory Traversal

* [dotdotpwn](https://github.com/wireghoul/dotdotpwn) - The Directory Traversal Fuzzer ![last-commit](https://img.shields.io/github/last-commit/wireghoul/dotdotpwn?style=flat)
* [slipit](https://github.com/usdAG/slipit) - Utility for creating ZipSlip archives. ![last-commit](https://img.shields.io/github/last-commit/usdAG/slipit?style=flat)

### Frameworks

* [Commix](https://github.com/commixproject/commix) - Automated All-in-One OS Command Injection Exploitation Tool. ![last-commit](https://img.shields.io/github/last-commit/commixproject/commix?style=flat)
* [TIDoS](https://github.com/0xInfection/TIDoS-Framework) - HTTP Request Smuggling Detection Tool. ![last-commit](https://img.shields.io/github/last-commit/0xInfection/TIDoS-Framework?style=flat)
* [tplmap](https://github.com/epinna/tplmap) - Server-Side Template Injection and Code Injection Detection and Exploit Tool. ![last-commit](https://img.shields.io/github/last-commit/epinna/tplmap?style=flat)

### Headers

* [Security Headers](https://securityheaders.com/) - Tool designed to help you better deploy and understand modern security features that are available for your website.

### Protocols

* [http-request-smuggling](https://github.com/anshumanpattnaik/http-request-smuggling) - HTTP Request Smuggling Detection Tool. ![last-commit](https://img.shields.io/github/last-commit/anshumanpattnaik/http-request-smuggling?style=flat)

### SSL/TLS

* [TLS-Scanner](https://github.com/tls-attacker/TLS-Scanner) - Assists in the evaluation of TLS Server configurations. ![last-commit](https://img.shields.io/github/last-commit/tls-attacker/TLS-Scanner?style=flat)

### LFI

* [LFISuite](https://github.com/D35m0nd142/LFISuite) - Automated scan and exploitation of Local File Inclusion. ![last-commit](https://img.shields.io/github/last-commit/D35m0nd142/LFISuite?style=flat)
* [LFIFreak](https://github.com/OsandaMalith/LFiFreak) - Local File Inclusion automation tool for PHP. ![last-commit](https://img.shields.io/github/last-commit/OsandaMalith/LFiFreak?style=flat)
* [Liffy](https://github.com/mzfr/liffy) - Local File Inclusion automation tool for PHP. ![last-commit](https://img.shields.io/github/last-commit/mzfr/liffy?style=flat)
