FuzzDB is an open-source dictionary and collection of fault injection patterns designed for dynamic application security testing. The tool provides comprehensive lists of attack payload primitives organized by attack type and platform, enabling security professionals to test applications for various vulnerabilities. The attack patterns database includes payloads for testing OS command injection, directory traversal, source code exposure, file upload bypass, authentication bypass, cross-site scripting (XSS), HTTP header CRLF injection, SQL injection, and NoSQL injection vulnerabilities. These patterns are categorized by attack type and platform where applicable. FuzzDB also contains discovery resources including dictionaries of predictable file and directory locations commonly found in standard software installations. This includes locations for log files, administrative directories, and other resources that are frequently placed in standard locations across different applications and platforms. The tool serves as a comprehensive resource for penetration testers and security researchers conducting fault injection testing and vulnerability assessments on web applications and other software systems.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
QIRA is a competitor to strace and gdb with MIT license, supporting Ubuntu and Docker for wider compatibility.
GuardDog is a CLI tool that identifies malicious PyPI and npm packages using heuristics-based analysis of source code and metadata.
Search engine for open-source Git repositories with advanced features like case sensitivity and regular expressions.
A brute-force protection middleware for express routes that rate-limits incoming requests.
AndroBugs Framework is an Android vulnerability analysis system that scans mobile applications for security vulnerabilities, missing best practices, and dangerous shell commands.
A Nuxt 3 security module that automatically implements OWASP security patterns through HTTP headers, middleware, and various protection mechanisms including CSP, XSS validation, CORS, and CSRF protection.
SearchCode is an extensive code search engine that indexes 75 billion lines of code from millions of projects to help developers find coding examples and libraries.
A technology lookup and lead generation tool that identifies the technology stack of any website and provides features for market research, competitor analysis, and data enrichment.
A source code search engine for searching alphanumeric snippets, signatures, or keywords in web page HTML, JS, and CSS code.