Ge0rg3 / hackthebox-writeupsLinks
A collection of writeups for active HTB boxes.
☆10Updated 6 years ago
Alternatives and similar repositories for hackthebox-writeups
Users that are interested in hackthebox-writeups are comparing it to the libraries listed below
Sorting:
- A BurpSuite extension for beautifying .NET message parameters and hiding some of the extra clutter that comes with .NET web apps (i.e. __…☆12Updated 10 years ago
- Scripts for OSCE☆18Updated 6 years ago
- Find unreferenced AWS S3 buckets which have CloudFront CNAME records pointing to them☆36Updated 7 years ago
- Code snippets I find useful☆31Updated 8 years ago
- A Burp Extender plugin that will allow you to tamper with requests containing compressed, serialized java objects.☆24Updated 6 years ago
- Quickly add http and https domains to BurpSuite's scope with all paths.☆16Updated 9 years ago
- eXtremely fast data eXtraction via blind SQL injection☆14Updated 13 years ago
- A burp extension to generate sqlmap PoC from target HTTP request.☆27Updated 8 years ago
- Just a place to share some things I've written while participating in Hack The Box.☆18Updated 5 years ago
- Enumerate subdomains through Virustotal☆32Updated 5 years ago
- Burp extension for automated handling of CSRF tokens☆16Updated 7 years ago
- Python tool for expired domain discovery in crossdomain.xml files☆23Updated 8 years ago
- Useful Windows and AD tools☆15Updated 3 years ago
- ☆38Updated 5 years ago
- ☆21Updated 5 years ago
- [PHP][Python] Root Exploiter – No Back-Connect☆10Updated 4 years ago
- Bug Bounty Clipboard☆17Updated 5 years ago
- A number of scripts POC's and problems solved as pentests move along.☆44Updated last year
- a parser + crawler for .DS_Store files exposed publically☆54Updated 2 years ago
- A bunch of tricks and configs to configure a work environment for web pentesting☆12Updated 7 years ago
- Standalone POCs/Exploits from various sources for Jok3r☆29Updated 4 years ago
- A playground to practice SSRF Attacks against web apps☆17Updated 6 years ago
- ☆11Updated 8 years ago
- Nmap NSE script to detect Pulse Secure SSL VPN file disclosure CVE-2019-11510☆18Updated 6 years ago
- A tool that can help detect and takeover subdomains with dead DNS records☆12Updated 7 years ago
- Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)☆25Updated 6 years ago
- A Burp Suite content discovery plugin that add the smart into the Buster!☆32Updated 7 years ago
- Unauthenticated RCE at Woody Ad Snippets / CVE-2019-15858 (PoC)☆32Updated 2 years ago
- A multi-threaded scanner that helps identify CORS flaws/misconfigurations☆19Updated 5 years ago
- Merge results from NMAP and Masscan into one CSV file☆18Updated 7 years ago