Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js
☆75Jan 21, 2024Updated 2 years ago
Alternatives and similar repositories for silent-spring
Users that are interested in silent-spring are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A collection of Server-Side Prototype Pollution gadgets and exploits☆234Feb 6, 2025Updated last year
- linux ebpf backdoor demo☆12Nov 20, 2024Updated last year
- TC39 proposal for mitigating prototype pollution☆53Aug 29, 2023Updated 2 years ago
- PoC☆12Apr 7, 2025Updated last year
- A proof-of-concept tool for detection and exploitation Object Injection Vulnerabilities in .NET applications☆63Jan 29, 2021Updated 5 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- DNS Tunneling as net.Conn☆16Dec 22, 2024Updated last year
- ODGen is a JavaScript Static Analysis tool to detect multiple types of vulnerabilities in Node.js packages.☆169Jan 29, 2024Updated 2 years ago
- pwn envs based on docker of ubuntu16.04,18.04,20.04☆10Dec 4, 2022Updated 3 years ago
- ☆22Nov 3, 2022Updated 3 years ago
- ☆29Aug 30, 2022Updated 3 years ago
- A python based minimal DNS server to test/verify DNS rebinding attacks☆85May 15, 2023Updated 3 years ago
- Exploit for CVE-2024-0402 in Gitlab☆15Mar 18, 2025Updated last year
- JAW: A Graph-based Security Analysis Framework for Client-side JavaScript☆118Feb 13, 2026Updated 4 months ago
- ☆24May 11, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆46Jan 2, 2022Updated 4 years ago
- ☆10Mar 5, 2023Updated 3 years ago
- kill AV/EDR☆20Jun 9, 2023Updated 3 years ago
- ☆17May 29, 2018Updated 8 years ago
- MacroExploit use in excel sheet☆20Jun 12, 2023Updated 3 years ago
- Challenges I wrote for various CTF competitions☆45Jul 21, 2024Updated last year
- 通过 ebpf(bcc) 在 TCP 包中插入 TOA,实现任意 TOA 伪造☆28Dec 12, 2023Updated 2 years ago
- recon.cloud is website that scans AWS, Azure and GCP public cloud footprint this GO tool only utilize its API for getting result to termi…☆23Feb 11, 2023Updated 3 years ago
- A variant analysis and visualisation tool that scans codebases for similar vulnerabilities☆73May 24, 2022Updated 4 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Shellcode execution via x86 inline assembly based on MSVC syntax☆17Apr 26, 2023Updated 3 years ago
- ☆31May 1, 2025Updated last year
- Some ReadObject Sink With JDBC☆245May 8, 2024Updated 2 years ago
- Awesome MXSS ??☆57Sep 30, 2024Updated last year
- Tools for Attacking Pleasant Password Server☆23Sep 19, 2023Updated 2 years ago
- GitHub Entreprise Server SAML authentication bypass (CVE-2025-23369) exploit☆38Feb 8, 2025Updated last year
- CodeQL extractor for java, which don't need to compile java source☆346Nov 25, 2022Updated 3 years ago
- Community Eventing and Scripting examples☆19Aug 11, 2025Updated 10 months ago
- ☆14Sep 11, 2019Updated 6 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆75Jun 17, 2025Updated last year
- A tool to search for gadgets, operations, and ROP chains using a backtracking algorithm in a tree-like structure☆19Jun 13, 2023Updated 3 years ago
- A vul-finder for loading CPG and automated finding vul-call-chains☆71Jul 22, 2025Updated 10 months ago
- Auto-generated CodeQL rules for matching CVE vulnerabilities and variants.☆184Sep 19, 2024Updated last year
- Some practices for ML Security, like XSS、Webshell detection...☆15Aug 28, 2019Updated 6 years ago
- Based on Lightspin proprietary data, research, and our tracking of cloud security trends in the market, our research team has compiled a …☆40Aug 8, 2022Updated 3 years ago
- attachments and (some) writeups/source code for RWCTF 5th☆59Jan 10, 2023Updated 3 years ago