13Sec Tools

Search Engine

Automate bug hunting using dorks from Google, Bing, Shodan, and more.

CSRF JFU

Simulate unauthorized file uploads using CSRF and jQuery-based methods.

Clickjacking

Test iframe protections like X-Frame-Options.

Exploit CORS

Check if CORS policies allow unintended cross-origin requests.

F5 Big-IP Cookie Encoder & Decoder

Encode or decode F5 Big-IP cookies to analyze session persistence.

DIOS Collection

A curated set of DIOS payloads for efficient SQL injection and data extraction.

Tabnabbing

Simulate tabnabbing attacks to test tab hijacking vulnerabilities.