All tools
23 cheatsheets in Web Application Security
Arjun
WebHTTP parameter discovery tool for finding hidden GET and POST parameters.
Burp Suite
WebIntegrated web proxy and testing platform for intercepting, modifying, and automating HTTP traffic.
Command Injection
WebOS command injection payloads, separators, blind detection, and filter bypasses for achieving RCE on authorized targets.
commix
WebAutomated command injection detection and exploitation in web parameters and headers.
Dalfox
WebFast parameter-based XSS scanner and proof-of-concept generator for web apps.
DroopeScan
WebCMS scanner focused on Drupal, Silverstripe, and WordPress plugin enumeration.
JoomScan
WebJoomla CMS vulnerability scanner and version or component enumerator.
JWT Attacks
WebJSON Web Token attacks: alg=none, weak secret cracking, key confusion (RS256→HS256), and claim tampering on authorized targets.
jwt_tool
WebJSON Web Token testing for algorithm confusion, weak secrets, and claim tampering.
LFI / Path Traversal
WebLocal file inclusion and directory traversal payloads, PHP wrappers, and log-poisoning RCE for authorized testing.
mitmproxy
WebInteractive TLS-capable HTTP proxy for intercepting, replaying, and scripting web traffic.
OWASP ZAP
WebOpen-source web app security proxy with passive/active scanning and automation API.
ParamSpider
WebMines archived URLs to extract unique parameters for a domain from web archives.
SQL Injection
WebManual SQL injection payloads and techniques for detection, UNION extraction, blind, and authentication bypass on authorized targets.
sqlmap
WebAutomated SQL injection detection and exploitation for web parameters, headers, and cookies.
SSRF (Server-Side Request Forgery)
WebServer-side request forgery payloads: cloud metadata access, internal port scanning, filter bypasses, and blind SSRF detection.
SSRFmap
WebSSRF exploitation framework with modules for cloud metadata, port scan, and shell.
tplmap
WebServer-Side Template Injection detection and exploitation for multiple template engines.
WPScan
WebWordPress security scanner for users, plugins, themes, and known vulnerabilities.
x8
WebHidden parameter discovery via response status, body, and reflection diffing.
XSS (Cross-Site Scripting)
WebCross-site scripting payloads and filter bypasses for reflected, stored, and DOM-based XSS on authorized targets.
XSStrike
WebAdvanced XSS detection with context analysis, fuzzing, and WAF-aware payload generation.
XXE (XML External Entity)
WebXML External Entity payloads for file read, SSRF, blind out-of-band exfiltration, and denial of service on authorized targets.