KishanBagaria / padding-oracle-attacker
🔓 CLI tool and library to execute padding oracle attacks easily, with support for concurrent network requests and an elegant UI.
☆205Updated last year
Alternatives and similar repositories for padding-oracle-attacker:
Users that are interested in padding-oracle-attacker are comparing it to the libraries listed below
- A natural evolution of Burp Suite's Repeater tool☆194Updated 11 months ago
- A bash script that automates the exfiltration of data over dns in case we have blind command execution on a server with egress filtering☆209Updated 4 years ago
- Burp extension to detect alias traversal via NGINX misconfiguration at scale.☆255Updated 3 years ago
- Use HTTP Smuggling Lab to learn HTTP Smuggling.☆346Updated 2 years ago
- DNS rebinding toolkit☆251Updated last year
- 🏴☠️ Bypass Same Origin Policy with DNS-rebinding to retrieve local server files 🏴☠️☆197Updated 5 years ago
- notes and code on past CTFs☆100Updated 3 years ago
- Everything you need about Burp Extension Generation☆152Updated 2 years ago
- CLI tool for PKCS7 padding oracle attacks☆135Updated 3 years ago
- Linux post exploitation privilege escalation enumeration☆255Updated 4 years ago
- Exporter is a Burp Suite extension to copy a request to a file or the clipboard as multiple programming languages functions.☆173Updated 3 years ago
- Linux privilege escalation via LXD☆132Updated 4 years ago
- Simple python script to extract unsafe functions from php projects☆197Updated 6 years ago
- ☆280Updated 3 years ago
- ☆128Updated 4 years ago
- ☆260Updated 5 years ago
- SSRF to TCP Port Scanning, Banner and Private IP Disclosure by abusing the FTP protocol/clients☆70Updated 3 years ago
- Multi-threaded Padding Oracle attacks against any service. Written in Rust.☆94Updated last year
- HTTP.ninja☆148Updated last year
- DupeKeyInjector☆135Updated 2 years ago
- Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.☆592Updated 3 years ago
- A list of files / paths to probe when arbitrary files can be read on a Microsoft Windows operating system☆200Updated last year
- One stop place for exploiting Jira instances in your proximity☆185Updated 7 months ago
- A Python implementation that facilitates finding timeless timing attack vulnerabilities.☆121Updated last year
- A mini webserver with FTP support for XXE payloads☆327Updated last year
- All my infosec notes I have been building up over the years☆328Updated 3 years ago
- This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes …☆256Updated 2 years ago
- Piper Burp Suite Extender plugin☆115Updated 10 months ago
- Viewgen is a ViewState tool capable of generating both signed and encrypted payloads with leaked validation keys☆594Updated last year
- Automatic tool for DNS rebinding-based SSRF attacks☆295Updated 4 years ago