Fuzzing for LFI using Burpsuite This repository contains a collection of tests for Local File Inclusion (LFI) vulnerabilities using Burp Suite. The tests are designed to help security researchers and developers identify and exploit LFI vulnerabilities in web applications. The repository includes a variety of tests, including: * Basic LFI tests: These tests demonstrate the basic principles of LFI and how to exploit it. * Advanced LFI tests: These tests demonstrate more advanced techniques for exploiting LFI vulnerabilities. * Real-world LFI tests: These tests demonstrate how to exploit LFI vulnerabilities in real-world web applications. The repository also includes a guide on how to use Burp Suite to identify and exploit LFI vulnerabilities. This repository is intended for security researchers and developers who want to learn more about LFI vulnerabilities and how to exploit them. Please note that this repository is for educational purposes only and should not be used to exploit vulnerabilities in production systems.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Chameleon aids in evading proxy categorization to bypass internet filters.
Learn how to create new Malleable C2 profiles for Cobalt Strike to avoid detection and signatured toolset
Create a vulnerable active directory for testing various Active Directory attacks.
MITRE Caldera™ is a cybersecurity platform that automates adversary emulation and supports red team operations through a modular framework built on MITRE ATT&CK.
A Live CD and Live USB for penetration testing and security assessment
SharpEDRChecker scans system components to detect security products and tools.
A set of YARA rules for identifying files containing sensitive information
Emulate offensive attack techniques in the cloud with a self-contained Go binary.
Open-source project for building instrumented environments to simulate attacks and test detections.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.