๐ŸŒ NullSec Web

February 27, 2026 ยท View on GitHub

๐ŸŒ NullSec Web

Advanced Web Application Security Toolkit

X/Twitter GitHub License

Go Rust Lua Kotlin

    โ–ˆโ–ˆโ–ˆโ–„    โ–ˆ  โ–ˆ    โ–ˆโ–ˆ  โ–ˆโ–ˆโ–“     โ–ˆโ–ˆโ–“      โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ โ–“โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ  โ–„โ–ˆโ–ˆโ–ˆโ–ˆโ–„  
    โ–ˆโ–ˆ โ–€โ–ˆ   โ–ˆ  โ–ˆโ–ˆ  โ–“โ–ˆโ–ˆโ–’โ–“โ–ˆโ–ˆโ–’    โ–“โ–ˆโ–ˆโ–’    โ–’โ–ˆโ–ˆ    โ–’ โ–“โ–ˆ   โ–€ โ–’โ–ˆโ–ˆโ–€ โ–€โ–ˆ  
   โ–“โ–ˆโ–ˆ  โ–€โ–ˆ โ–ˆโ–ˆโ–’โ–“โ–ˆโ–ˆ  โ–’โ–ˆโ–ˆโ–‘โ–’โ–ˆโ–ˆโ–‘    โ–’โ–ˆโ–ˆโ–‘    โ–‘ โ–“โ–ˆโ–ˆโ–„   โ–’โ–ˆโ–ˆโ–ˆ   โ–’โ–“โ–ˆ    โ–„ 
   โ–“โ–ˆโ–ˆโ–’  โ–โ–Œโ–ˆโ–ˆโ–’โ–“โ–“โ–ˆ  โ–‘โ–ˆโ–ˆโ–‘โ–’โ–ˆโ–ˆโ–‘    โ–’โ–ˆโ–ˆโ–‘      โ–’   โ–ˆโ–ˆโ–’โ–’โ–“โ–ˆ  โ–„ โ–’โ–“โ–“โ–„ โ–„โ–ˆโ–ˆโ–’
   โ–’โ–ˆโ–ˆโ–‘   โ–“โ–ˆโ–ˆโ–‘โ–’โ–’โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–“ โ–‘โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–’โ–‘โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–’โ–’โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–’โ–’โ–‘โ–’โ–ˆโ–ˆโ–ˆโ–ˆโ–’โ–’ โ–“โ–ˆโ–ˆโ–ˆโ–€ โ–‘
   โ–‘ โ–’โ–‘   โ–’ โ–’ โ–‘โ–’โ–“โ–’ โ–’ โ–’ โ–‘ โ–’โ–‘โ–“  โ–‘โ–‘ โ–’โ–‘โ–“  โ–‘โ–’ โ–’โ–“โ–’ โ–’ โ–‘โ–‘โ–‘ โ–’โ–‘ โ–‘โ–‘ โ–‘โ–’ โ–’  โ–‘
     โ–‘    โ–‘    โ–‘   โ–‘   โ–‘         โ–‘            โ–‘   โ–‘   โ–‘        
   โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„โ–„
   โ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘ W E B โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–ˆ
   โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€โ–€
                       bad-antics

๐Ÿ”“ Join x.com/AnonAntics for premium features!


๐ŸŽฏ Features

ToolLanguageDescriptionFreePremium
dirfuzzGoDirectory/file bruteforcerโœ…๐Ÿ”ฅ
sqlmap-ngRustSQL injection detectionโœ…๐Ÿ”ฅ
xsshunterGoXSS vulnerability scannerโœ…๐Ÿ”ฅ
paraminerGoParameter discoveryโœ…๐Ÿ”ฅ
crawlerRustDeep web crawlerโœ…๐Ÿ”ฅ
httpprobeGoHTTP probing & fingerprintโœ…๐Ÿ”ฅ

๐Ÿ“ Structure

nullsec-web/
โ”œโ”€โ”€ go/
โ”‚   โ”œโ”€โ”€ dirfuzz/         # Directory fuzzer
โ”‚   โ”œโ”€โ”€ xsshunter/       # XSS scanner
โ”‚   โ”œโ”€โ”€ paraminer/       # Parameter mining
โ”‚   โ””โ”€โ”€ httpprobe/       # HTTP prober
โ”œโ”€โ”€ rust/
โ”‚   โ”œโ”€โ”€ sqlmap_ng/       # SQLi detection
โ”‚   โ”œโ”€โ”€ crawler/         # Web crawler
โ”‚   โ””โ”€โ”€ vulnscan/        # Vulnerability scanner
โ”œโ”€โ”€ python/
โ”‚   โ”œโ”€โ”€ jwt_exploit.py   # JWT exploitation
โ”‚   โ”œโ”€โ”€ ssrf_scan.py     # SSRF detection
โ”‚   โ”œโ”€โ”€ header_inject.py # Header injection
โ”‚   โ””โ”€โ”€ cors_check.py    # CORS misconfiguration
โ””โ”€โ”€ wordlists/
    โ”œโ”€โ”€ directories.txt  # Common directories
    โ”œโ”€โ”€ parameters.txt   # Common parameters
    โ””โ”€โ”€ payloads/        # Attack payloads

๐Ÿš€ Quick Start

# Directory fuzzing
./dirfuzz -u https://target.com -w wordlists/directories.txt

# SQL injection scan
./sqlmap-ng -u "https://target.com/page?id=1" --dbs

# XSS hunting
./xsshunter -u https://target.com -w wordlists/xss.txt

# Parameter discovery
./paraminer -u https://target.com --all

# Web crawling
./crawler -u https://target.com -d 3 -o urls.txt

๐Ÿ”ง Tool Details

dirfuzz (Go) - Directory Fuzzer

Features:

  • Recursive scanning
  • Extension fuzzing
  • Custom wordlists
  • Response filtering
  • Rate limiting
# Basic scan
./dirfuzz -u https://target.com -w common.txt

# With extensions
./dirfuzz -u https://target.com -w files.txt -x php,asp,jsp

# Recursive + filtered
./dirfuzz -u https://target.com -w dirs.txt -r -fc 404,403

# High speed
./dirfuzz -u https://target.com -w big.txt -t 100 --rate 1000

sqlmap-ng (Rust) - SQLi Scanner

Detection methods:

  • Boolean-based blind
  • Time-based blind
  • Error-based
  • UNION query
  • Stacked queries
# Auto detection
./sqlmap-ng -u "https://target.com/item?id=1"

# Specific technique
./sqlmap-ng -u "https://target.com/item?id=1" --technique=BT

# Database enumeration
./sqlmap-ng -u "https://target.com/item?id=1" --dbs --tables

# Data extraction
./sqlmap-ng -u "https://target.com/item?id=1" -D dbname -T users --dump

For authorized security testing only. Only test applications you have permission to assess.


NullSec Framework | GitHub | X/Twitter