DigitalInterruption / cookie-monster
A utility for automating the testing and re-signing of Express.js cookie secrets.
☆59Updated 2 years ago
Alternatives and similar repositories for cookie-monster
Users that are interested in cookie-monster are comparing it to the libraries listed below
Sorting:
- LFI to RCE via phpinfo() assistance or via controlled log file☆66Updated 2 years ago
- ☆31Updated 4 years ago
- A simple NodeJS WebSocket WebApp vulnerable to blind SQL injection☆70Updated 4 years ago
- InfluxDB CVE-2019-20933 vulnerability exploit☆39Updated 3 years ago
- ☆34Updated 3 years ago
- ☆39Updated 2 years ago
- User enumeration and password spraying tool for testing Azure AD☆69Updated 3 years ago
- Tool to enable blind sql injection attacks against websockets using sqlmap☆60Updated 2 weeks ago
- Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1☆57Updated last year
- A Python based ingestor for BloodHound☆84Updated 2 years ago
- ☆39Updated last year
- Umbraco CMS 7.12.4 - (Authenticated) Remote Code Execution☆75Updated 4 years ago
- NotSoCereal: A Deserialization exploit playground☆52Updated 3 years ago
- ☆51Updated 2 years ago
- ☆26Updated last year
- ☆29Updated 4 years ago
- This script implements the Proof of Concept attack from the Checkpoint research "NTLM Credentials Theft via PDF Files"☆27Updated 7 years ago
- A list of "secrets" from JWT sample code and readme files.☆55Updated 4 years ago
- ☆25Updated 2 years ago
- SAMBA Symlink Directory Traversal Manual Exploitation☆31Updated 5 years ago
- ElasticSearch exploit and Pentesting guide for penetration tester☆27Updated 2 years ago
- A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.☆50Updated 4 years ago
- Local File Inclusion Burp-Suite Intruder Payload Generator Plugin☆40Updated 4 years ago
- Multi-threaded, IPv6 aware, wordlists/single-user username enumeration via CVE-2018-15473☆108Updated last year
- Collection of username lists for enumerating kerberos domain users☆91Updated 7 years ago
- Impersonating authentication over HTTP and/or named pipes.☆133Updated 4 years ago
- Shell Simulation over Net-SNMP with extend functionality☆96Updated 4 years ago
- Python script for exploiting Werkzeug Debug RCE useful for CTF☆35Updated 5 years ago
- Creates a malicious ODF document help leak NetNTLM Creds☆31Updated last year
- The following package is the standalone wordlist-only component to flask-unsign.☆39Updated 11 months ago