KTH-LangSec / server-side-prototype-pollution
A collection of Server-Side Prototype Pollution gadgets and exploits
☆134Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for server-side-prototype-pollution
- Awesome MXSS ??☆45Updated last month
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆120Updated this week
- CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.☆107Updated 4 months ago
- PP-finder Help you find gadget for prototype pollution exploitation☆138Updated 3 months ago
- Challenges I wrote for various CTF competitions☆40Updated 4 months ago
- Bambdas collection for Burp Suite Professional and Community.☆206Updated 3 weeks ago
- ☆88Updated 11 months ago
- ☆65Updated last month
- Searcher for cross-site leaks (XS-Leaks)☆81Updated last year
- This repository stores some of my custom BCheck Scan configurations. Its goal is to identify intriguing elements that warrant further man…☆86Updated 9 months ago
- The Template Injection Table is intended to help during the testing of an application for template injection vulnerabilities.☆65Updated 8 months ago
- CVE-2023-33733 reportlab RCE☆113Updated last year
- Same Origin XSS challenge☆56Updated 2 years ago
- A rapid HTTP downgrade smuggling scanner written in Go.☆246Updated 6 months ago
- Header Exploitation HTTP☆143Updated last week
- A chrome/Firefox extension to retrieve and load react javascript chunks all at once for a wide range of javascript techs☆60Updated 4 months ago
- ☆130Updated 2 weeks ago
- Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.☆177Updated last month
- Some tips for Bug Bounty using LibreOffice☆33Updated this week
- HTTP/2 Single Packet Attack low Level Library / Tool based on Scapy + Exploit Timing Attacks☆147Updated 2 weeks ago
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆44Updated last week
- Here i will post my writeups :)☆31Updated last year
- lightyear is a tool to dump files in tedious (blind) conditions using PHP filters☆60Updated 2 weeks ago
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js☆57Updated 10 months ago
- Useful configurations for the DomLogger++ extension☆30Updated 2 months ago
- This is the data that powers the PortSwigger URL validation bypass cheat sheet.☆30Updated last month
- This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.☆54Updated last year
- jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice☆245Updated 7 months ago
- Enumerate / Dump Docker Registry☆163Updated 7 months ago
- ☆143Updated last month