Tool · activeactivehigh-riskopt-in
THC-Hydra
Network login brute-forcer (THC-Hydra) for many protocols.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
High risk of account lockouts, WAF bans, and terms-of-service violations. Requires explicit authorization and small, targeted inputs.
Tagsactive
More tools
- CommixactiveAutomated command-injection detection and exploitation.
- CorsyactiveScans for CORS misconfigurations.
- CRLFuzzactiveProbes for CRLF injection and HTTP response splitting.
- DalfoxactiveXSS scanner for reflected, stored and DOM input surfaces with structured PoC output.
- GhauriactiveFast automated SQL-injection detection and exploitation, an sqlmap alternative.
- gowitnessactiveHeadless screenshot capture of web targets.