Skip to content

bad-antics/nullsec-web

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

2 Commits
Β 
Β 
Β 
Β 

Repository files navigation

🌐 NullSec Web

Advanced Web Application Security Toolkit

Discord GitHub License

Go Rust Lua Kotlin

    β–ˆβ–ˆβ–ˆβ–„    β–ˆ  β–ˆ    β–ˆβ–ˆ  β–ˆβ–ˆβ–“     β–ˆβ–ˆβ–“      β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β–“β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ  β–„β–ˆβ–ˆβ–ˆβ–ˆβ–„  
    β–ˆβ–ˆ β–€β–ˆ   β–ˆ  β–ˆβ–ˆ  β–“β–ˆβ–ˆβ–’β–“β–ˆβ–ˆβ–’    β–“β–ˆβ–ˆβ–’    β–’β–ˆβ–ˆ    β–’ β–“β–ˆ   β–€ β–’β–ˆβ–ˆβ–€ β–€β–ˆ  
   β–“β–ˆβ–ˆ  β–€β–ˆ β–ˆβ–ˆβ–’β–“β–ˆβ–ˆ  β–’β–ˆβ–ˆβ–‘β–’β–ˆβ–ˆβ–‘    β–’β–ˆβ–ˆβ–‘    β–‘ β–“β–ˆβ–ˆβ–„   β–’β–ˆβ–ˆβ–ˆ   β–’β–“β–ˆ    β–„ 
   β–“β–ˆβ–ˆβ–’  β–β–Œβ–ˆβ–ˆβ–’β–“β–“β–ˆ  β–‘β–ˆβ–ˆβ–‘β–’β–ˆβ–ˆβ–‘    β–’β–ˆβ–ˆβ–‘      β–’   β–ˆβ–ˆβ–’β–’β–“β–ˆ  β–„ β–’β–“β–“β–„ β–„β–ˆβ–ˆβ–’
   β–’β–ˆβ–ˆβ–‘   β–“β–ˆβ–ˆβ–‘β–’β–’β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–“ β–‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–’β–‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–’β–’β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–’β–’β–‘β–’β–ˆβ–ˆβ–ˆβ–ˆβ–’β–’ β–“β–ˆβ–ˆβ–ˆβ–€ β–‘
   β–‘ β–’β–‘   β–’ β–’ β–‘β–’β–“β–’ β–’ β–’ β–‘ β–’β–‘β–“  β–‘β–‘ β–’β–‘β–“  β–‘β–’ β–’β–“β–’ β–’ β–‘β–‘β–‘ β–’β–‘ β–‘β–‘ β–‘β–’ β–’  β–‘
     β–‘    β–‘    β–‘   β–‘   β–‘         β–‘            β–‘   β–‘   β–‘        
   β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„β–„
   β–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘ W E B β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–ˆ
   β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€β–€
                       bad-antics

πŸ”“ Join discord.gg/killers for premium features!


🎯 Features

Tool Language Description Free Premium
dirfuzz Go Directory/file bruteforcer βœ… πŸ”₯
sqlmap-ng Rust SQL injection detection βœ… πŸ”₯
xsshunter Go XSS vulnerability scanner βœ… πŸ”₯
paraminer Go Parameter discovery βœ… πŸ”₯
crawler Rust Deep web crawler βœ… πŸ”₯
httpprobe Go HTTP probing & fingerprint βœ… πŸ”₯

πŸ“ Structure

nullsec-web/
β”œβ”€β”€ go/
β”‚   β”œβ”€β”€ dirfuzz/         # Directory fuzzer
β”‚   β”œβ”€β”€ xsshunter/       # XSS scanner
β”‚   β”œβ”€β”€ paraminer/       # Parameter mining
β”‚   └── httpprobe/       # HTTP prober
β”œβ”€β”€ rust/
β”‚   β”œβ”€β”€ sqlmap_ng/       # SQLi detection
β”‚   β”œβ”€β”€ crawler/         # Web crawler
β”‚   └── vulnscan/        # Vulnerability scanner
β”œβ”€β”€ python/
β”‚   β”œβ”€β”€ jwt_exploit.py   # JWT exploitation
β”‚   β”œβ”€β”€ ssrf_scan.py     # SSRF detection
β”‚   β”œβ”€β”€ header_inject.py # Header injection
β”‚   └── cors_check.py    # CORS misconfiguration
└── wordlists/
    β”œβ”€β”€ directories.txt  # Common directories
    β”œβ”€β”€ parameters.txt   # Common parameters
    └── payloads/        # Attack payloads

πŸš€ Quick Start

# Directory fuzzing
./dirfuzz -u https://target.com -w wordlists/directories.txt

# SQL injection scan
./sqlmap-ng -u "https://target.com/page?id=1" --dbs

# XSS hunting
./xsshunter -u https://target.com -w wordlists/xss.txt

# Parameter discovery
./paraminer -u https://target.com --all

# Web crawling
./crawler -u https://target.com -d 3 -o urls.txt

πŸ”§ Tool Details

dirfuzz (Go) - Directory Fuzzer

Features:

  • Recursive scanning
  • Extension fuzzing
  • Custom wordlists
  • Response filtering
  • Rate limiting
# Basic scan
./dirfuzz -u https://target.com -w common.txt

# With extensions
./dirfuzz -u https://target.com -w files.txt -x php,asp,jsp

# Recursive + filtered
./dirfuzz -u https://target.com -w dirs.txt -r -fc 404,403

# High speed
./dirfuzz -u https://target.com -w big.txt -t 100 --rate 1000

sqlmap-ng (Rust) - SQLi Scanner

Detection methods:

  • Boolean-based blind
  • Time-based blind
  • Error-based
  • UNION query
  • Stacked queries
# Auto detection
./sqlmap-ng -u "https://target.com/item?id=1"

# Specific technique
./sqlmap-ng -u "https://target.com/item?id=1" --technique=BT

# Database enumeration
./sqlmap-ng -u "https://target.com/item?id=1" --dbs --tables

# Data extraction
./sqlmap-ng -u "https://target.com/item?id=1" -D dbname -T users --dump

⚠️ Legal Disclaimer

For authorized security testing only. Only test applications you have permission to assess.


NullSec Framework | GitHub | Discord

About

NullSec web security toolkit - discord.gg/killers

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages