Workshop given at Hack in Paris 2019
☆126Jun 8, 2023Updated 2 years ago
Alternatives and similar repositories for xxe-workshop
Users that are interested in xxe-workshop are comparing it to the libraries listed below
Sorting:
- Workshop on Template Injection (6 exercises) covering Twig, Jinja2, Tornado, Velocity and Freemaker engines.☆127Jan 10, 2023Updated 3 years ago
- ☆11Jan 24, 2023Updated 3 years ago
- References, tools and sample payloads☆11Sep 16, 2016Updated 9 years ago
- Scripts and misc. stuff related to the PortSwigger Web Academy☆17Feb 6, 2022Updated 4 years ago
- List DTDs and generate XXE payloads using those local DTDs.☆648Feb 21, 2024Updated 2 years ago
- Material from presentations done by GoSecure researchers☆34Oct 10, 2023Updated 2 years ago
- An easy to navigate list of unicode characters that have risky transformations 💥☆25Mar 22, 2022Updated 3 years ago
- Minimalist cheat sheet for developpers to write secure code☆54Jul 17, 2020Updated 5 years ago
- ☆20Jan 24, 2022Updated 4 years ago
- ☆12Mar 31, 2021Updated 4 years ago
- GetSimple CMS Custom JS Plugin Exploit RCE Chain☆11Mar 8, 2023Updated 2 years ago
- Exploit scripts☆12Apr 10, 2022Updated 3 years ago
- Accompanying material needed for the workshop☆11Jun 14, 2023Updated 2 years ago
- Compiled dataset of Java deserialization CVEs☆60Aug 31, 2020Updated 5 years ago
- ☆18Apr 26, 2021Updated 4 years ago
- ☆15Apr 13, 2021Updated 4 years ago
- 一些漏洞的环境/利用工具/分析☆10Jul 24, 2020Updated 5 years ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆952Dec 31, 2021Updated 4 years ago
- Burp Suite Extensions☆12Oct 19, 2021Updated 4 years ago
- AWS S3 open bucket poc automated script.☆56Aug 23, 2021Updated 4 years ago
- Toolkit to detect and keep track on Blind XSS, XXE & SSRF☆293Aug 23, 2019Updated 6 years ago
- Custom scripts for the PIPER Burp extensions.☆97Sep 24, 2023Updated 2 years ago
- Material for the training "Developing Burp Suite Extensions – From Manual Testing to Security Automation"☆356Oct 14, 2020Updated 5 years ago
- Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practis…☆1,676May 24, 2025Updated 9 months ago
- CVE, reports, research☆15Mar 17, 2021Updated 4 years ago
- ☆562Mar 27, 2025Updated 11 months ago
- ☆694Jul 4, 2022Updated 3 years ago
- DLL Exports Extraction BOF with optional NTFS transactions.☆90Nov 5, 2021Updated 4 years ago
- ☆105Oct 18, 2020Updated 5 years ago
- Exploit for CVE-2021-3129☆285Jan 29, 2021Updated 5 years ago
- ☆27Jun 18, 2024Updated last year
- Oracle Database Penetration Testing Reference (10g/11g)☆40Jul 28, 2018Updated 7 years ago
- xss development frameworks, with the goal of making payload writing easier.☆153Aug 7, 2024Updated last year
- This lab is created to demonstrate pass-the-hash, blind sql and SSTI vulnerabilities☆93Jun 11, 2023Updated 2 years ago
- code reviews to practice☆18Jul 22, 2021Updated 4 years ago
- ☆21Dec 15, 2020Updated 5 years ago
- My cyber security notes.☆14Feb 22, 2025Updated last year
- ☆18Feb 14, 2019Updated 7 years ago
- CVE-2022-32119 - Arox-Unrestricted-File-Upload☆17Dec 20, 2023Updated 2 years ago