0x00-0x00 / CVE-2016-2098
Ruby On Rails unrestricted render() exploit
☆16Updated 6 years ago
Alternatives and similar repositories for CVE-2016-2098:
Users that are interested in CVE-2016-2098 are comparing it to the libraries listed below
- Parse X509 certificates to get the (sub)domains in it.☆28Updated 6 years ago
- Everything about xss protection technology☆15Updated 5 years ago
- Burp extension for automated handling of CSRF tokens☆16Updated 6 years ago
- A Burp Extender plugin that will allow you to tamper with requests containing compressed, serialized java objects.☆24Updated 5 years ago
- A simple scanner to find and brute force tomcat manager logins☆28Updated 5 years ago
- Burp Suite Professional extension in Java for Tabnabbing attack☆13Updated 6 years ago
- Python tool for expired domain discovery in crossdomain.xml files☆23Updated 7 years ago
- Abusing SketchUp to make persistence on Windows☆21Updated 5 years ago
- ☆19Updated 4 years ago
- A BurpSuite extension for beautifying .NET message parameters and hiding some of the extra clutter that comes with .NET web apps (i.e. __…☆12Updated 9 years ago
- Apfell implant written in C#.☆8Updated 4 years ago
- All about CVE-2018-14667; From what it is to how to successfully exploit it.☆50Updated 6 years ago
- String or worldlist encoder for use in fuzzing or web application testing☆17Updated 5 years ago
- RCE in NPM VSCode Extension☆20Updated 3 years ago
- A simple grep user interface for searching code which can be used for SAST.☆8Updated 5 years ago
- ADD/SUB encoder for alphanumeric shellcode☆9Updated 5 years ago
- Two Proof-Of-Concepts of SUID binary vulnerabilities on BMC Patrol allowing to elevate privileges from any linux user to root.☆12Updated 4 years ago
- Burp Extension for copying requests safely. It redacts headers like Cookie, Authorization and X-CSRF-Token for now. More support can be a…☆17Updated 4 years ago
- This repository contains some details about abusing outlook.☆27Updated 6 years ago
- Some talks about security☆13Updated 4 years ago
- A playground to practice SSRF Attacks against web apps☆17Updated 6 years ago
- Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)☆24Updated 5 years ago
- An information gathering tool to collect git emails in version control host services☆11Updated 5 years ago
- Supporting material for the "Hunting Bugs In The Tropics" DEFCON 30 talk☆9Updated 2 years ago
- This repository contains hit lists to use for web application content discovery.☆11Updated 7 years ago
- Magento Security Scanner☆15Updated 3 years ago
- ☆22Updated 2 years ago
- Convert Empire profiles to Apache mod_rewrite scripts☆27Updated 5 years ago