IOActive / jdwp-shellifier
☆853Updated last year
Alternatives and similar repositories for jdwp-shellifier:
Users that are interested in jdwp-shellifier are comparing it to the libraries listed below
- Java RMI enumeration and attack tool.☆730Updated 7 years ago
- All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities☆780Updated 3 years ago
- Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC).☆500Updated 3 years ago
- J2EEScan is a plugin for Burp Suite Proxy. The goal of this plugin is to improve the test coverage during web application penetration tes…☆651Updated last year
- A byte code analyzer for finding deserialization gadget chains in Java applications☆1,020Updated 3 years ago
- A collection of curated Java Deserialization Exploits☆593Updated 3 years ago
- A tool to dump Java serialization streams in a more human readable form.☆1,014Updated 9 months ago
- Java Message Exploitation Tool☆498Updated 2 years ago
- TCP tunneling over HTTP/HTTPS for web application servers☆734Updated 8 years ago
- SHELLING - a comprehensive OS command injection payload generator☆443Updated 5 years ago
- Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.☆1,610Updated 3 months ago
- ☆469Updated last year
- Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans☆575Updated 3 years ago
- A tool for embedding XXE/XML exploits into different filetypes☆1,072Updated 3 months ago
- TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.☆1,604Updated 10 months ago
- Collection of bypass gadgets to extend and wrap ysoserial payloads☆351Updated 2 years ago
- Content hijacking proof-of-concept using Flash, PDF and Silverlight☆381Updated 5 years ago
- Add headers to all Burp requests to bypass some WAF products☆331Updated 7 years ago
- There is no pre-auth RCE in Jenkins since May 2017, but this is the one!☆602Updated 5 years ago
- Rogue MySql Server☆469Updated 11 years ago
- an IIS shortname Scanner☆544Updated 2 years ago
- Redis 4.x/5.x RCE☆950Updated 3 years ago
- MySQL fake server for read files of connected clients☆592Updated 7 years ago
- The great impacket example scripts compiled for Windows☆948Updated 6 years ago
- Automated HTTP Request Repeating With Burp Suite☆869Updated 3 years ago
- Redis(<=5.0.5) RCE☆1,038Updated last year
- A CVE-2016-5195 exploit example.☆325Updated 8 years ago
- JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool☆2,450Updated 5 years ago
- Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.☆595Updated 4 years ago
- Simple reverse ICMP shell☆1,572Updated 6 years ago